nest-boot-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of documentation, guidelines, and code examples for structuring NestJS projects. It does not include any executable scripts, tool definitions, or automated actions.
  • [DATA_EXPOSURE]: The documentation mentions checking environment variables and .env files in the context of domain renames. This is listed as a manual verification step for developers and does not involve automated access or exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to guide an agent through user-requested code refactoring. 1. Ingestion points: User prompts describing refactoring tasks (e.g., evals/evals.json). 2. Boundary markers: Absent in the static guidelines. 3. Capability inventory: The skill itself does not define any tools. 4. Sanitization: None provided. This surface is inherent to the skill's purpose and is mitigated by the inclusion of comprehensive manual verification checklists (references/renames.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:51 AM
Security Audit — agent-trust-hub — nest-boot-best-practices