trpc-scaffolder
Scaffold Type-Safe tRPC Endpoints
Manual tRPC setup creates repetitive router, schema, and registration work. This skill scaffolds consistent tRPC and Zod structures and checks basic project integration.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "trpc-scaffolder" from https://skillstore.io/skills/ariegoldkin-trpc-scaffolder.md and its manifest at https://skillstore.io/api/skills/ariegoldkin-trpc-scaffolder/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "trpc-scaffolder". Create a user router.
Expected outcome:
- A user router file with a typed procedure placeholder.
- Registration and schema follow-up steps.
Using "trpc-scaffolder". Create schemas for a paginated question list.
Expected outcome:
- Input schema guidance for limit and cursor values.
- Output schema guidance for questions and the next cursor.
- Inferred type export guidance.
Using "trpc-scaffolder". Validate the current tRPC setup.
Expected outcome:
A report of discovered routers, missing registration entries, schema files, and missing type exports.
Security Audit
CriticalMost static alerts are documentation syntax, relative imports, fixed project paths, or safe local validation commands. However, unescaped sed programs permit command execution, and unvalidated names permit path traversal. Public profile examples also omit authorization, and one error example exposes upstream details.
Confirmed security concerns (4)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Filesystem access (37)
โ๏ธ External commands (50)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/ariegoldkin-trpc-scaffolder/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/ariegoldkin-trpc-scaffolder?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/ariegoldkin-trpc-scaffolder?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/ariegoldkin-trpc-scaffolder/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/ariegoldkin-trpc-scaffolder.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
ArieGoldkin. (2026). trpc-scaffolder security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/ariegoldkin-trpc-scaffolder/audits/9BibTeX citation
@techreport{ariegoldkin-ariegoldkin-trpc-scaffolder-2026,
author = {ArieGoldkin},
title = {trpc-scaffolder security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/ariegoldkin-trpc-scaffolder/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "trpc-scaffolder security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "ArieGoldkin"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/ariegoldkin-trpc-scaffolder/audits/9"
identifiers:
- type: other
value: "skillstore:ariegoldkin-trpc-scaffolder:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create a feature router
Generate a router skeleton and registration guidance for a new application domain.
Define endpoint contracts
Create Zod input and output schema structures before implementing server behavior.
Review tRPC consistency
Check router registration, exported schema types, naming, authorization, and validation patterns.
Try These Prompts
Create a Zod schema for [entity] with these fields: [fields]. Export inferred input and output types.
Add a [query or mutation] named [procedure] to [router]. Define its input, output, and required error cases.
Scaffold [feature] with a router, Zod schemas, procedures, registration steps, and validation. Use protected procedures for sensitive operations.
Review [module path] for schema coverage, authorization, error disclosure, registration, pagination, and tests. Propose focused corrections before editing.
Best Practices
- Replace every generated placeholder before using an endpoint.
- Use protected procedures and ownership checks for sensitive data.
- Run validation, TypeScript checks, and tests after scaffolding.
Avoid
- Do not pass untrusted or unvalidated names to the bundled scripts.
- Do not expose account reads or mutations through public procedures.
- Do not treat the validation script as a complete build or security check.
Frequently Asked Questions
Does this install tRPC or Zod?
Does the router generator update _app.ts?
Does the procedure script edit an existing router?
Can it generate protected procedures?
What does validation check?
Which names are safe for the scripts?
Developer Details
Author
ArieGoldkinLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
89edfdc710d0846129dcee6a929477b04f08052c
Maintenance freshness
7/24/2026
Usage
7 downloads ยท 234 views
File structure
๐ docs/
๐ quick-start-guide.md
๐ trpc-patterns.md
๐ examples/
๐ good-router.ts
๐ good-schema.ts
๐ README.md
๐ scripts/
๐ add-procedure.sh
๐ create-router.sh
๐ create-schema.sh
๐ validate-trpc.sh
๐ SKILL.md
๐ templates/
๐ procedure.snippet
๐ router.ts.template
๐ schema.ts.template