upstash-qstash
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill follows security best practices by recommending the use of environment variables for API tokens and signing keys instead of hardcoding them.
- [SAFE]: The skill includes a dedicated section on security ('Sharp Edges') that explicitly warns against processing unverified webhooks and provides instructions for implementing cryptographic signature verification using the
@upstash/qstashSDK. - [SAFE]: The skill provides legitimate development patterns for serverless environments (Next.js, Cloudflare Workers) and correctly identifies architectural requirements for public endpoints.
Audit Metadata