security-core

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a security guidance and utility repository, providing educational content and templates for building secure applications.
  • [COMMAND_EXECUTION]: The script scripts/generate_jwt_keys.sh uses openssl to generate cryptographically secure signing keys locally. It includes safety features like automatically updating .gitignore to prevent private keys from being committed.
  • [COMMAND_EXECUTION]: The script scripts/audit_security.sh facilitates local security reviews by executing well-known dependency scanners (npm audit, pip-audit, cargo-audit) and searching for hardcoded credentials using ripgrep within the provided project directory.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly promotes secure secret management, warning against hardcoded credentials and demonstrating how to use environment variables, .env files (with .gitignore), and dedicated secret managers like AWS Secrets Manager or HashiCorp Vault.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 12:36 PM
Security Audit — agent-trust-hub — security-core