upstash-ratelimit-js

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical guide for the Upstash Rate Limit SDK (@upstash/ratelimit). It provides documentation on algorithms, pricing, and features without any malicious instructions or hidden behaviors.
  • [CREDENTIALS_UNSAFE]: No sensitive credentials or API keys are hardcoded in the skill files. Examples use safe placeholders like '' or follow industry best practices by referencing environment variables (e.g., process.env.UPSTASH_TOKEN).
  • [EXTERNAL_DOWNLOADS]: The skill mentions an automatic IP protection feature that fetches data from the well-known 'ipsum' repository on GitHub. This is a standard security practice for IP-based abuse prevention and is part of the tool's core functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes identifiers such as User IDs, IP addresses, and User Agents for rate-limiting purposes. These inputs are used as keys for counting and comparison within the SDK logic and are not interpreted as commands or instructions by the agent, presenting no injection risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:07 PM
Security Audit — agent-trust-hub — upstash-ratelimit-js