secure-code-guardian
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements industry-standard authentication patterns using
bcryptfor password hashing andjsonwebtokenfor secure session management. It correctly instructs users to store secrets in environment variables rather than hardcoding them. - [SAFE]: Secure input handling is demonstrated through the use of
Zodfor schema validation and parameterized SQL queries to prevent injection attacks. The examples explicitly warn against string interpolation in database queries. - [SAFE]: The skill provides comprehensive defensive guidance for preventing common web vulnerabilities, including Cross-Site Scripting (XSS) via
DOMPurifyand Content Security Policy (CSP), as well as Cross-Site Request Forgery (CSRF) through SameSite cookie attributes and token validation. - [SAFE]: Command injection and path traversal prevention techniques are correctly illustrated, recommending safe alternatives like
execFileand path normalization over vulnerable shell-based functions. - [SAFE]: The instruction set includes practical validation checkpoints for developers to verify security controls, such as checking for privilege escalation paths and rate-limiting triggers.
Audit Metadata