api-security-best-practices
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing best practices for API security. It demonstrates how to prevent common vulnerabilities like SQL injection and XSS through secure coding patterns.
- [CREDENTIALS_UNSAFE]: The skill follows security best practices by explicitly instructing users to store sensitive credentials like JWT secrets in environment variables (
process.env.JWT_SECRET) rather than hardcoding them. - [EXTERNAL_DOWNLOADS]: The skill references standard, well-known industry libraries for Node.js (e.g.,
jsonwebtoken,bcrypt,zod,helmet,express-rate-limit) as part of its educational examples. It does not perform any automated downloads or execution of remote code.
Audit Metadata