express-backend-starter

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [SAFE]: The skill is a comprehensive guide for scaffolding production-ready Node.js/Express applications with a strong focus on security best practices, including input validation, secure headers, and environment variable management.- [EXTERNAL_DOWNLOADS]: Recommends the installation of standard, well-known industry packages from the NPM registry such as Express, Helmet, CORS, and Zod.- [COMMAND_EXECUTION]: Instructs the agent to perform standard development tasks such as project scaffolding, package installation via NPM, and running the application using Node.js built-in features like --watch and --env-file.- [PROMPT_INJECTION]: No attempts to override system prompts or bypass safety guidelines were found; the instructions use authoritative language strictly for architectural emphasis.- [DATA_EXFILTRATION]: No evidence of unauthorized data access or external transmission of sensitive information; instructions explicitly advise redacting secrets from logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 02:30 PM