t3-code-patterns

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill provides detailed guidance on secure development, including environment variable validation using @t3-oss/env and encrypted secret management with dotenvx. It includes proactive security disclosures regarding tool-level risks, such as shell substitution in dotenvx, and provides actionable mitigations for developers.
  • [COMMAND_EXECUTION]: Includes shell-based pre-commit hooks (templates/pre-commit-block-db-push.sh and templates/pre-commit-block-ts-migrations.sh) designed to enforce migration-based database workflows and prevent accidental or destructive schema modifications.
  • [EXTERNAL_DOWNLOADS]: Recommends using npx react-doctor@latest for code audits, which involves fetching a diagnostic package from the well-known npm registry during the development process.
  • [REMOTE_CODE_EXECUTION]: Suggests executing react-doctor via npx, a standard development pattern that involves downloading and running remote code to evaluate repository health and maintainability.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — t3-code-patterns