nestjs-coding-standard
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines architectural and coding standards without introducing security vulnerabilities. It includes explicit instructions to avoid logging PII or sensitive credentials.
- [PROMPT_INJECTION]: As a code review skill, it naturally processes external code (ingestion point: code review requests). However, it lacks tools for execution or modification (capability: Read only), and its primary purpose is informative, minimizing the risk of indirect injection exploitation. No specific boundary markers or programmatic sanitization are defined in the static text.
- [DATA_EXFILTRATION]: No network operations or sensitive data access patterns were found. The skill reinforces secure configuration management via environment variables.
- [REMOTE_CODE_EXECUTION]: The skill does not perform external downloads or execute dynamic code at runtime.
Audit Metadata