secure-oauth-oidc
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis of external, untrusted data including source code, metadata, and configuration files as specified in the review protocols (e.g., references/review-and-delivery.md). This creates an ingestion point for potentially malicious instructions. There are no explicit boundary markers or warnings provided to separate these inputs from the agent context. While the skill possesses a capability inventory limited to information analysis with no integrated executable scripts, it provides no sanitization logic for processing natural language instructions found in the untrusted data, relying only on user-led redaction of secrets.
- [NO_CODE]: The skill consists entirely of markdown documentation and configuration files. It does not include or execute any scripts, binaries, or automated code components.
- [SAFE]: No malicious patterns such as credential exfiltration, obfuscated commands, or unauthorized remote code execution were identified. The skill adheres to security best practices by referencing official industry standards (IETF, OIDC) and instructing the user to redact sensitive information during reviews.
Audit Metadata