backend-development
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (SAFE): No malicious patterns or security risks were identified. The skill acts as a set of reference documents and best-practice instructions for developers.\n- [PROMPT_INJECTION] (SAFE): No instructions designed to override system prompts, bypass safety filters, or jailbreak the agent were found. The constraints included are safety-reinforcing (e.g., mandates for parameterized queries).\n- [DATA_EXPOSURE] (SAFE): No sensitive data, hardcoded credentials, or private file paths were detected. Code examples correctly use environment variable placeholders like 'process.env.SESSION_SECRET'.\n- [REMOTE_CODE_EXECUTION] (SAFE): No patterns of remote code execution, untrusted downloads, or suspicious script sourcing were found. External links point to reputable documentation and standards bodies (OWASP, NIST, OAuth.net).\n- [OBFUSCATION] (SAFE): The content is clear and readable. No multi-layer encoding, homoglyphs, or zero-width character techniques were detected.\n- [INDIRECT_PROMPT_INJECTION] (SAFE): The skill is entirely static and does not implement tools or functions that ingest and process untrusted external data.
Audit Metadata