nestjs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a legitimate development resource for the NestJS framework. The included Python validation script and documentation are benign and follow established safety patterns (e.g., using yaml.safe_load).
- [INDIRECT_PROMPT_INJECTION]: The skill ingests codebase and documentation content, which is a known attack surface for indirect prompt injection. This capability is essential for its primary function as a coding assistant and is mitigated by the underlying model's safety guardrails.
- [COMMAND_EXECUTION]: Mentions of shell commands are limited to official framework tools (e.g., nest CLI) and are consistent with the skill's stated purpose.
Audit Metadata