sa-token-api-security
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional, providing configuration snippets and Java code examples for implementing security features using the Sa-Token library.
- [EXTERNAL_DOWNLOADS]: The documentation references official repositories from the dromara/sa-token project on GitHub. Additionally, the evaluation-report.html file loads Tailwind CSS from a well-known CDN (cdn.tailwindcss.com). These are recognized and safe external resources.
- [CREDENTIALS_UNSAFE]: Example secret keys (e.g., 'kQwIOrYvnXmSDkwEiFngrKidMcdrgKor' and 'JfdDSgfCmPsDfmsAaQwnXk') are present in the documentation files. However, the skill explicitly warns in the 'Gotchas' section of SKILL.md that these secrets must not be hardcoded in production and should be managed via configuration centers or environment variables, indicating safe instructional use.
Audit Metadata