skills/fabricioctelles/skills/auth-md/Gen Agent Trust Hub

auth-md

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the retrieval of protocol specifications from official documentation sites (auth-md.com and workos.com) and the WorkOS GitHub repository. These are authoritative sources for the protocol being implemented.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for using the isitagentready.com API, which is a public validator service for the auth.md protocol.
  • [PROMPT_INJECTION]: The validation workflow is designed to ingest and analyze external auth.md files from local paths or URLs. While this represents an ingestion point for untrusted data, the risk is mitigated by the skill's specific design for structural and field-level validation against a strict schema.
  • Ingestion points: The validation workflow in SKILL.md (Workflow: Validate) processes files and URLs.
  • Boundary markers: The skill identifies required headings (e.g., '# auth.md') as delimiters for the protocol content.
  • Capability inventory: The skill does not possess capabilities to write files or execute shell commands based on the ingested content.
  • Sanitization: Ingested content is subjected to structural, field, and consistency validation rules defined in the reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:03 PM
Security Audit — agent-trust-hub — auth-md