nodejs-express-server
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [SAFE]: The skill provides architectural patterns and templates for building Node.js applications. It promotes best practices such as hiding stack traces in production environment error handlers and implementing JWT-based authentication.
- [COMMAND_EXECUTION]: The file
scripts/security-checklist.shis a shell utility that outputs a security checklist to a file or standard output. The script is benign and uses standard shell safety flags (set -euo pipefail). - [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection because it is designed to ingest user requirements to generate server-side code. It uses the provided reference files as context for code generation.
- Ingestion points: User instructions for API routes, database schemas, and server logic.
- Boundary markers: Standard Markdown headers and fenced code blocks are used to separate reference material.
- Capability inventory: The skill provides templates for creating RESTful APIs and includes a shell script utility for generating text checklists.
- Sanitization: No specific sanitization logic is implemented in the skill templates; the agent relies on its primary safety guidelines when generating code from these patterns.
- [CREDENTIALS_UNSAFE]: Reference code in
references/database-integration-postgresql-with-sequelize.mdandreferences/authentication-with-jwt.mduses environment variables (process.env.DB_PASS,process.env.JWT_SECRET) for secrets management. The skill explicitly advises using environment variables instead of hardcoding sensitive data in code, which is an industry-standard security practice.
Audit Metadata