tls-pinning
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as an educational resource for mobile security hardening. It focuses on Subject Public Key Info (SPKI) pinning, which is the recommended method to maintain security while avoiding service disruption during standard certificate updates.\n- [SAFE]: The document suggests robust recovery mechanisms, including the shipment of backup pins and the implementation of remote kill switches, which are industry-standard practices to prevent application lockout during unforeseen key rotations.\n- [COMMAND_EXECUTION]: The skill includes a standard
opensslcommand pipeline for developers to manually generate pinning hashes for their specific domains. This is a benign administrative utility command.\n- [SAFE]: No automated downloads, remote code execution patterns, or data exfiltration attempts were identified. All library references (OkHttp, TrustKit, Dio) are standard tools within the mobile development ecosystem and are used correctly in the provided examples.
Audit Metadata