nodejs-security-audit
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands, specifically
grep, to scan source code files (.js,.ts) for patterns indicative of security risks like hardcoded passwords, tokens, and API keys. This is the core functionality of the audit tool. - [SAFE]: The skill provides legitimate security remediation advice and code snippets for common web vulnerabilities (XSS, CORS, Rate Limiting, Security Headers) based on industry standards like the OWASP Top 10.
- [SAFE]: No network operations, external script downloads, or unauthorized file access attempts were identified. All operations are confined to the auditing of provided source code.
Audit Metadata