api-security-best-practices

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing best practices for API security. It demonstrates how to prevent common vulnerabilities like SQL injection and XSS through secure coding patterns.
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices by explicitly instructing users to store sensitive credentials like JWT secrets in environment variables (process.env.JWT_SECRET) rather than hardcoding them.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, well-known industry libraries for Node.js (e.g., jsonwebtoken, bcrypt, zod, helmet, express-rate-limit) as part of its educational examples. It does not perform any automated downloads or execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — api-security-best-practices