nodejs-express-server

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [SAFE]: The skill provides architectural patterns and templates for building Node.js applications. It promotes best practices such as hiding stack traces in production environment error handlers and implementing JWT-based authentication.
  • [COMMAND_EXECUTION]: The file scripts/security-checklist.sh is a shell utility that outputs a security checklist to a file or standard output. The script is benign and uses standard shell safety flags (set -euo pipefail).
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection because it is designed to ingest user requirements to generate server-side code. It uses the provided reference files as context for code generation.
  • Ingestion points: User instructions for API routes, database schemas, and server logic.
  • Boundary markers: Standard Markdown headers and fenced code blocks are used to separate reference material.
  • Capability inventory: The skill provides templates for creating RESTful APIs and includes a shell script utility for generating text checklists.
  • Sanitization: No specific sanitization logic is implemented in the skill templates; the agent relies on its primary safety guidelines when generating code from these patterns.
  • [CREDENTIALS_UNSAFE]: Reference code in references/database-integration-postgresql-with-sequelize.md and references/authentication-with-jwt.md uses environment variables (process.env.DB_PASS, process.env.JWT_SECRET) for secrets management. The skill explicitly advises using environment variables instead of hardcoding sensitive data in code, which is an industry-standard security practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — nodejs-express-server