hey-api-openapi-contract-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides extensive security recommendations for managing API keys and tokens, explicitly advising against hardcoding secrets in configuration files and emphasizing the use of environment variables.
  • [SAFE]: It promotes secure development practices by suggesting the use of CI/CD checks (e.g., git diff --exit-code) to ensure generated code is not modified outside of the intended process.
  • [SAFE]: The guidelines include warnings against insecure practices like disabling TLS verification (NODE_TLS_REJECT_UNAUTHORIZED=0) and logging sensitive headers or tokens.
  • [SAFE]: External dependencies referenced, such as @hey-api/openapi-ts, zod, and @tanstack/svelte-query, are well-known and legitimate packages within the Node.js ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:30 PM
Security Audit — agent-trust-hub — hey-api-openapi-contract-debugging