nestjs

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on providing architectural and security best practices for NestJS development, emphasizing modularity, type safety, and standardized error handling.
  • [EXTERNAL_DOWNLOADS]: The documentation references standard, reputable Node.js packages from the official npm registry (such as @nestjs/common, helmet, joi, and passport). These are well-established libraries in the JavaScript ecosystem used for framework functionality, security hardening, and validation.
  • [COMMAND_EXECUTION]: Includes standard development lifecycle commands (e.g., npm run build, npm run test, npm run lint). These are standard parts of the JavaScript development process and do not involve arbitrary or suspicious command strings.
  • [PROMPT_INJECTION]: No patterns associated with prompt injection, safety bypasses, or system prompt extraction were detected in the instructions or metadata.
  • [DATA_EXFILTRATION]: The skill explicitly instructs users to avoid hardcoding secrets and to use environment variables or dedicated secret management services, following security best practices.
  • [SAFE]: The use of search tools like ripgrep (rg) is limited to inspecting the skill's own local reference files provided in the skill package.
  • [SAFE]: Indirect prompt injection surface exists as the skill ingests user input and generates code. Ingestion points: User prompts for code generation. Boundary markers: The skill emphasizes the use of DTOs and ValidationPipe as mandatory input boundaries. Capability inventory: Code generation and local file searching (rg). Sanitization: Recommends whitelist, forbidNonWhitelisted, and validation decorators (e.g., @IsEmail).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — nestjs