node

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a best-practices guide and does not contain any malicious instructions or obfuscated code.
  • [EXTERNAL_DOWNLOADS]: Recommends several industry-standard Node.js packages and tools for logging, performance, and debugging (e.g., pino, autocannon, piscina, zod). These are well-established community resources.
  • [CREDENTIALS_UNSAFE]: The instructions for environment configuration in rules/environment.md use dummy placeholders (e.g., your-api-key-here, sk-dev-key-123) and local development connection strings. It explicitly advises against committing secrets to version control, which is a security best practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for processing external data streams (e.g., CSV/ETL pipelines). While this constitutes a data ingestion surface, the provided code snippets demonstrate safe parsing techniques and do not include instructions that would cause an agent to execute embedded data commands.
  • [COMMAND_EXECUTION]: Mentions the use of CLI tools like autocannon and @platformatic/flame via npx. These are legitimate developer tools used for benchmarking and profiling within a controlled environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:17 PM
Security Audit — agent-trust-hub — node