sa-token-integration
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill functions as a static developer guide for the Sa-Token security framework. The provided instructions, configuration examples, and reference files are consistent with legitimate software documentation practices and do not contain executable malicious code.
- [CREDENTIALS_UNSAFE]: The documentation includes hardcoded sample credentials and dummy secrets intended for configuration examples. These are not active production secrets and are accompanied by explicit warnings.
- Evidence:
jwt-secret-key: asdasdasifhueuiwyurfewbfjsdafjkinexamples/integration-demo.mdandreferences/jwt-extend.md. - Evidence: Default credentials
sa/123456for the 'Quick-Login' feature documented inSKILL.mdwith instructions to modify them for production use. - [EXTERNAL_DOWNLOADS]: The skill contains references to official repositories and well-known service CDNs.
- Evidence: Documentation links to the official Sa-Token GitHub organization (
github.com/dromara/sa-token). - Evidence: The
evaluation-report.htmlfile loads styling resources from a well-known CDN (https://cdn.tailwindcss.com).
Audit Metadata