heartwood-auth
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill integrates with vendor-owned infrastructure, specifically the
grove.placedomains and@autumnsgrove/latticelibraries, which are consistent with the identified author. - [SAFE]: Security best practices for secret management are followed, instructing users to use environment variables (
HEARTWOOD_CLIENT_SECRET) and secure secret storage tools likewrangler secret putrather than hardcoding sensitive data. - [SAFE]: Code examples demonstrate robust input handling by using Zod schema validation and safe JSON parsing utility functions to process external API responses.
- [SAFE]: The hardcoded credential strings provided in the documentation are explicitly labeled as examples for demonstration purposes and are not active secrets.
Audit Metadata