spring-boot
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard architectural advice and implementation patterns for modern Java development using Spring Boot.
- [CREDENTIALS_SAFE]: The skill correctly uses environment variable placeholders (e.g.,
${PAYMENT_API_KEY}) for sensitive configuration instead of hardcoding secrets. - [DATA_EXPOSURE]: The skill promotes the use of DTOs/records to avoid exposing internal JPA entities to API responses, which is a key security practice.
- [COMMAND_EXECUTION]: No shell commands or arbitrary execution logic is present. Only standard build tool examples (mvn/gradle) are provided as documentation.
- [PROMPT_INJECTION]: The skill uses natural instructional language without attempting to override system prompts or bypass safety filters.
Audit Metadata