backend-auth
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes high-security standards by recommending Argon2id or Bcrypt for password hashing while explicitly advising against weak algorithms like MD5 or SHA1.
- [SAFE]: Instructions for token management correctly prioritize the use of httpOnly, Secure, and SameSite cookie attributes to mitigate XSS and CSRF vulnerabilities, and provide specific warnings against storing sensitive data in localStorage.
- [SAFE]: The tool-based codebase inspection using grep and glob is appropriately scoped to identify existing authentication patterns (e.g., jwt, passport, session) and does not involve unauthorized access to sensitive system files or credentials.
- [SAFE]: The skill includes comprehensive implementation steps for secure flows, such as PKCE for OAuth 2.0, account lockout mechanisms to prevent brute-force attacks, and audit logging for sensitive security events.
Audit Metadata