heartwood-auth

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill integrates with vendor-owned infrastructure, specifically the grove.place domains and @autumnsgrove/lattice libraries, which are consistent with the identified author.
  • [SAFE]: Security best practices for secret management are followed, instructing users to use environment variables (HEARTWOOD_CLIENT_SECRET) and secure secret storage tools like wrangler secret put rather than hardcoding sensitive data.
  • [SAFE]: Code examples demonstrate robust input handling by using Zod schema validation and safe JSON parsing utility functions to process external API responses.
  • [SAFE]: The hardcoded credential strings provided in the documentation are explicitly labeled as examples for demonstration purposes and are not active secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 09:47 PM
Security Audit — agent-trust-hub — heartwood-auth