secure-code-guardian

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements industry-standard authentication patterns using bcrypt for password hashing and jsonwebtoken for secure session management. It correctly instructs users to store secrets in environment variables rather than hardcoding them.
  • [SAFE]: Secure input handling is demonstrated through the use of Zod for schema validation and parameterized SQL queries to prevent injection attacks. The examples explicitly warn against string interpolation in database queries.
  • [SAFE]: The skill provides comprehensive defensive guidance for preventing common web vulnerabilities, including Cross-Site Scripting (XSS) via DOMPurify and Content Security Policy (CSP), as well as Cross-Site Request Forgery (CSRF) through SameSite cookie attributes and token validation.
  • [SAFE]: Command injection and path traversal prevention techniques are correctly illustrated, recommending safe alternatives like execFile and path normalization over vulnerable shell-based functions.
  • [SAFE]: The instruction set includes practical validation checkpoints for developers to verify security controls, such as checking for privilege escalation paths and rate-limiting triggers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — secure-code-guardian