node
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a best-practices guide and does not contain any malicious instructions or obfuscated code.
- [EXTERNAL_DOWNLOADS]: Recommends several industry-standard Node.js packages and tools for logging, performance, and debugging (e.g.,
pino,autocannon,piscina,zod). These are well-established community resources. - [CREDENTIALS_UNSAFE]: The instructions for environment configuration in
rules/environment.mduse dummy placeholders (e.g.,your-api-key-here,sk-dev-key-123) and local development connection strings. It explicitly advises against committing secrets to version control, which is a security best practice. - [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for processing external data streams (e.g., CSV/ETL pipelines). While this constitutes a data ingestion surface, the provided code snippets demonstrate safe parsing techniques and do not include instructions that would cause an agent to execute embedded data commands.
- [COMMAND_EXECUTION]: Mentions the use of CLI tools like
autocannonand@platformatic/flamevianpx. These are legitimate developer tools used for benchmarking and profiling within a controlled environment.
Audit Metadata