env-config-agent
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed with a strong security posture for managing sensitive environment variables. It explicitly instructs the agent to redact secret values (using '***'), read only key structures, and never echo values in output.
- [SAFE]: All write operations (e.g., creating .env.example or typed env files) require explicit user approval, minimizing the risk of unauthorized file modifications.
- [SAFE]: The skill references well-known and trusted development practices, such as using
@t3-oss/env-nextjsandzodfor environment variable validation. - [SAFE]: External links point to the vendor's official GitHub repository (
bh611627) and their published npm package, which are treated as safe vendor resources according to standard analysis rules.
Audit Metadata