erpnext-errors-hooks

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational documentation and code patterns for Frappe/ERPNext framework development. It does not contain any executable code or instructions that could harm the agent or the host environment.\n- [SAFE]: Explicitly identifies and provides mitigations for SQL injection vulnerabilities in hook implementations, specifically recommending the use of frappe.db.escape() for user-provided data.\n- [SAFE]: Promotes best practices for system availability by detailing how to handle errors in sensitive hooks like extend_bootinfo and permission handlers, ensuring that a failure in a custom hook does not crash the entire application UI.\n- [SAFE]: Includes guidance on secure transaction handling and mandatory error logging for background processes where user feedback is unavailable.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 05:37 PM