better-auth
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The initialization script
scripts/better_auth_init.pygenerates TypeScript configuration code by directly interpolating user input frominput()calls into code templates. This allows for arbitrary code injection in the resultingauth.tsfile if the input is not carefully sanitized. - Evidence: In the
_prompt_direct_dbmethod, thedb_pathvariable is placed directly into a string literal within the configuration:f'database: new Database("{db_path}")'. Similarly, the_prompt_mongodbmethod interpolatesdb_namedirectly into thedatabaseNameproperty. - [DATA_EXFILTRATION]: The
better_auth_init.pyscript attempts to load environment variables from sensitive locations, including.claude/.envand.claude/skills/.env. Reading environment files from these paths can expose the agent's internal configuration and credentials. - Evidence: The
_load_env_filesmethod inscripts/better_auth_init.pydefines a list of paths includingself.project_root / ".claude" / ".env"and iterates through them to parse their contents. - [COMMAND_EXECUTION]: The skill includes an unnecessary binary file
scripts/.coveragewhich contains metadata and absolute file paths from the author's local development environment. Such binary files can be used for obfuscation or to influence the behavior of testing tools like coverage.py. - Evidence: Hex analysis of the
.coveragefile reveals a SQLite database containing local paths such as/mnt/d/www/claudekit/claudekit-engineer/.claude/skills/better-auth/scripts/better_auth_init.py.
Recommendations
- AI detected serious security threats
Audit Metadata