upstash-qstash
Pass
Audited by Gen Agent Trust Hub on Feb 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): Analysis of the skill instructions and reference files reveals no malicious intent or security vulnerabilities. The skill explicitly promotes security-first development.
- [DATA_EXFILTRATION] (SAFE): The skill contains logic to detect and prevent hardcoded credentials in code it reviews or generates. It recommends using environment variables for all sensitive tokens and signing keys.
- [REMOTE_CODE_EXECUTION] (SAFE): No remote code execution patterns found. The skill relies on the official @upstash/qstash package for its functionality.
- [PROMPT_INJECTION] (SAFE): Instructions are strictly focused on domain expertise and do not attempt to override system prompts or bypass safety guardrails.
Audit Metadata