monday-code-init

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements critical multi-tenant isolation patterns by instructing the agent to include accountId filters in all database queries to prevent cross-tenant data exposure.
  • [SAFE]: Employs official vendor libraries (@mondaycom/apps-sdk, monday-sdk-js) and recommended security tools like the SecretsManager and EnvironmentVariablesManager for handling sensitive configuration.
  • [SAFE]: Scaffolding logic uses standard package managers (npm) to install well-known and vendor-maintained dependencies without executing arbitrary remote scripts.
  • [SAFE]: Follows security best practices for local development by providing .env.example templates and using mock data for development contexts rather than production credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 03:26 PM
Security Audit — agent-trust-hub — monday-code-init