security-core
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a security guidance and utility repository, providing educational content and templates for building secure applications.
- [COMMAND_EXECUTION]: The script
scripts/generate_jwt_keys.shusesopensslto generate cryptographically secure signing keys locally. It includes safety features like automatically updating.gitignoreto prevent private keys from being committed. - [COMMAND_EXECUTION]: The script
scripts/audit_security.shfacilitates local security reviews by executing well-known dependency scanners (npm audit,pip-audit,cargo-audit) and searching for hardcoded credentials usingripgrepwithin the provided project directory. - [CREDENTIALS_UNSAFE]: The documentation explicitly promotes secure secret management, warning against hardcoded credentials and demonstrating how to use environment variables,
.envfiles (with.gitignore), and dedicated secret managers like AWS Secrets Manager or HashiCorp Vault.
Audit Metadata