env-config-agent

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed with a strong security posture for managing sensitive environment variables. It explicitly instructs the agent to redact secret values (using '***'), read only key structures, and never echo values in output.
  • [SAFE]: All write operations (e.g., creating .env.example or typed env files) require explicit user approval, minimizing the risk of unauthorized file modifications.
  • [SAFE]: The skill references well-known and trusted development practices, such as using @t3-oss/env-nextjs and zod for environment variable validation.
  • [SAFE]: External links point to the vendor's official GitHub repository (bh611627) and their published npm package, which are treated as safe vendor resources according to standard analysis rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:03 AM
Security Audit — agent-trust-hub — env-config-agent