backend-dev-guidelines
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Architectural enforcement of a layered structure (Routes, Controllers, Services, Repositories) promotes separation of concerns and improves system security by defining clear boundaries for data flow and logic execution.
- [SAFE]: Mandatory use of Zod for validating all external request data (body, query, params, webhooks) effectively prevents common injection and malformed data attacks at the entry points of the application.
- [SAFE]: The UnifiedConfig pattern centralizes configuration and secrets management, explicitly discouraging the direct use of environment variables across the codebase and promoting the use of .gitignore for sensitive files.
- [SAFE]: Integration with Sentry for observability and error tracking follows industry standards for maintaining secure and reliable production environments, including PII protection measures like scrubbing sensitive headers.
- [SAFE]: Testing guidelines mandate unit and integration testing for services and critical routes, ensuring that security-sensitive logic remains verifiable and stable.
Audit Metadata