mfa-on-mobile
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical guide for implementing secure MFA, recommending industry-standard practices such as RFC 6238 TOTP, hardware-backed keystores, and phishing-resistant FIDO2/Passkeys.
- [SAFE]: The provided Kotlin code for TOTP generation is a standard implementation of the TOTP algorithm and does not contain any malicious logic or hidden behaviors.
- [SAFE]: References to platform-specific APIs and libraries (e.g., react-native-passkey) are appropriate for the skill's stated purpose and do not represent a supply chain risk.
Audit Metadata