constructive-security
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a technical reference for the Constructive Authz protocol and SDK, focusing on the configuration of secure database access controls.
- [SAFE]: Detailed documentation is provided for implementing defensive measures such as GuardStepUp (MFA/password verification) and DataLock (row-level protection) to prevent unauthorized mutations.
- [SAFE]: The documentation includes security warnings against potentially insecure configurations, such as the use of unconditional 'AllowAll' policies or array-based membership lists, and recommends relational foreign-key based policies instead.
- [SAFE]: All SDK examples and blueprint snippets are legitimate and directly related to the skill's purpose of managing entity-scoped security and authorization.
Audit Metadata