agency-identity-access-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively promotes established security standards (OAuth 2.0, OIDC, SAML 2.0, SCIM, WebAuthn) and explicitly forbids insecure practices like hand-rolling cryptography or token formats.
  • [SAFE]: Code examples correctly implement security controls, such as verifying state and nonce parameters to prevent CSRF and replay attacks, and using PKCE for authorization code flows.
  • [SAFE]: The skill uses safe patterns for secret management, instructing the use of environment variables (process.env.OIDC_CLIENT_ID) rather than hardcoded credentials.
  • [SAFE]: References to the @simplewebauthn/server library are appropriate for implementing WebAuthn and are consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-identity-access-engineer