req-http-client

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for the legitimate Elixir library Req. All code demonstrates standard library usage without malicious intent.
  • [SAFE]: No hardcoded credentials were found; the skill correctly demonstrates using Application.get_env and Application.fetch_env! for sensitive data like API tokens, which is a security best practice for Elixir applications.
  • [SAFE]: Network operations are directed towards placeholders (e.g., api.example.com) for instructional purposes. The instructions emphasize that these are placeholders and should not be replaced with real host secrets in commits.
  • [SAFE]: The skill enforces secure testing practices by requiring the use of Req.Test to stub every external call, ensuring the test suite does not hit real APIs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:25 AM
Security Audit — agent-trust-hub — req-http-client