t3-env
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides detailed guidance on using the T3 Env library (
@t3-oss/env-core,@t3-oss/env-nextjs,@t3-oss/env-nuxt) for type-safe environment variable validation. It correctly highlights security best practices, such as ensuring server-side secrets are not exposed to the client and using specific prefixes for framework-specific public variables. - [EXTERNAL_DOWNLOADS]: The skill references documentation and services from well-known and trusted providers including Vercel, Netlify, Railway, Fly.io, and Supabase. These references are informative and align with the primary purpose of the skill.
- [DATA_EXPOSURE]: While the skill involves handling environment variables, it explicitly instructs the agent and user to use validation schemas and to separate sensitive data. It uses common placeholders for credentials in examples and does not include any hardcoded secrets or malicious exfiltration patterns.
- [COMMAND_EXECUTION]: The skill suggests using repository-owned commands and standard package managers like
bunfor project inspection and dependency management. No suspicious or high-risk command execution patterns (likesudoor piping remote scripts to shells) were detected.
Audit Metadata