security-review
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely educational and documentation-based, providing patterns for secure coding and infrastructure configuration.
- [SAFE]: Code examples labeled as 'FAIL' or 'DANGEROUS' are clearly marked and used to illustrate vulnerabilities for avoidance, which is a standard pedagogical approach in security training.
- [SAFE]: All external libraries and tools referenced (such as Zod, DOMPurify, Supabase, and AWS SDKs) are industry-standard, well-known, and reputable.
- [SAFE]: No hidden instructions, prompt injections, or unauthorized network operations were identified in the files.
- [SAFE]: The skill encourages security best practices such as least privilege, secrets rotation, and input validation.
Audit Metadata