sa-token-integration

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill functions as a static developer guide for the Sa-Token security framework. The provided instructions, configuration examples, and reference files are consistent with legitimate software documentation practices and do not contain executable malicious code.
  • [CREDENTIALS_UNSAFE]: The documentation includes hardcoded sample credentials and dummy secrets intended for configuration examples. These are not active production secrets and are accompanied by explicit warnings.
  • Evidence: jwt-secret-key: asdasdasifhueuiwyurfewbfjsdafjk in examples/integration-demo.md and references/jwt-extend.md.
  • Evidence: Default credentials sa/123456 for the 'Quick-Login' feature documented in SKILL.md with instructions to modify them for production use.
  • [EXTERNAL_DOWNLOADS]: The skill contains references to official repositories and well-known service CDNs.
  • Evidence: Documentation links to the official Sa-Token GitHub organization (github.com/dromara/sa-token).
  • Evidence: The evaluation-report.html file loads styling resources from a well-known CDN (https://cdn.tailwindcss.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:33 PM
Security Audit — agent-trust-hub — sa-token-integration