nestjs-api-dev
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates a dedicated security convention (
SECURITY_CONVENTION.md) that mandates robust protections, including JWT refresh token rotation, bcrypt password hashing, and parameterized queries to prevent SQL injection. - [SAFE]: All identified dependencies, such as
big.jsfor financial calculations andhelmetfor security headers, are well-known, industry-standard libraries appropriate for their stated use cases. - [SAFE]: The use of vendor-specific packages, such as
@sellernote/sellernote-nestjs-api-property, is consistent with the skill's authorship and is documented as a standard component of the vendor's development ecosystem. - [SAFE]: The skill enforces secure transport practices (HTTPS, CORS whitelisting, and secure cookie attributes) and provides clear guidelines for protecting against common web vulnerabilities like XSS and Path Traversal.
Audit Metadata