auth-handbook
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill primarily functions as a technical reference guide, providing architectural recommendations for Next.js authentication such as the use of httpOnly cookies, PKCE for OAuth, and server-side RBAC enforcement.- [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository data to provide contextual advice, which creates a minor attack surface for indirect prompt injection.
- Ingestion points: The skill accesses local project files through the repo-files tool to identify existing auth patterns and libraries (SKILL.md).
- Boundary markers: There are no explicit delimiters or boundary markers defined to isolate repo content from the agent's instructions.
- Capability inventory: The skill is restricted to the repo-files tool, limiting potential impact.
- Sanitization: No specific sanitization or filtering of repo content is described, although the skill's primary output is static design guidance.
Audit Metadata