security-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a reference guide for security best practices. It includes examples of vulnerable configurations contrasted with secure implementations for Express.js, Nginx, Docker, and AWS S3.
- [SAFE]: No external packages or remote code executions are defined. The examples provided (e.g., helmet, cors) are standard, well-known libraries in the Node.js ecosystem used for enhancing security.
- [SAFE]: The command examples (e.g.,
curl,aws s3api) are provided for testing and auditing purposes within the user's own environment, and no credentials or sensitive paths are hardcoded for exfiltration.
Audit Metadata