e-signature

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local utility script, scripts/verify.sh, which uses shell commands to perform static security analysis on generated code. The script executes grep and bash to check for security anti-patterns like hardcoded secrets or missing webhook verification. These operations are limited to the local filesystem and intended for development verification.
  • [EXTERNAL_DOWNLOADS]: The documentation recommends the use of official software development kits (SDKs) from trusted sources. It references docusign-esign and @dropbox/sign from well-known official package registries.
  • [SAFE]: The skill promotes several security best practices throughout its instructions. It provides explicit warnings against hardcoding sensitive credentials (API keys, private keys) and recommends using environment variables or secret stores. It includes detailed instructions and code examples for implementing HMAC signature verification on incoming webhooks to prevent data tampering. It enforces a sandbox-first approach to prevent accidental billing or unintended communication with real users during development.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — e-signature