nitro
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a framework that ingests untrusted data via HTTP request bodies (e.g.,
event.req.json()). While it mentions security best practices like using parameterized queries for databases to prevent SQL injection, the surface for processing external data is inherent to the framework's purpose. - Ingestion points: Request handlers in
routes/andapi/(described inreferences/core-routing.md). - Boundary markers: None specific to the prompt, but Nitro uses standard HTTP request/response boundaries.
- Capability inventory: File system access (via
unstorage), database operations (viadb0), and network requests (viafetch). - Sanitization: Documentation specifically recommends using
db.sqltagged templates for safe, parameterized queries. - [DYNAMIC_EXECUTION]: The documentation for the experimental Rendu template engine in
references/core-rendering.mddescribes the use of server-side script tags (<script server>) which allow executing code within templates. This is a documented feature of the framework being described. - [CREDENTIALS_UNSAFE]: The routing documentation in
references/core-routing.mdincludes an example ofbasicAuthconfiguration using generic placeholders:"username": "admin"and"password": "secret". These are provided for illustrative purposes in the reference material and do not represent actual secrets.
Audit Metadata