abac-access-control

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes documentation and configuration examples that reference official container images for Open Policy Agent (openpolicyagent/opa) and Envoy Proxy (envoyproxy/envoy) from their respective official registries. It also lists established and verifiable libraries such as casbin and @openpolicyagent/opa-wasm as dependencies for implementation.
  • [COMMAND_EXECUTION]: The instructions provide practical examples of shell commands for policy management tasks, including benchmarking (hey), testing (opa test), and formatting (opa fmt). These commands are standard tools within the OPA ecosystem and are used in the context of developer workflows and CI/CD pipelines.
  • [SAFE]: No malicious patterns, prompt injections, or unauthorized data access attempts were found. The skill emphasizes security best practices for authorization, such as the "default deny" principle, sourcing subject attributes from authenticated tokens (JWT), and calculating environment attributes server-side to prevent client-side manipulation. While the skill includes several extremely repetitive reference files, these appear to be placeholder content or data inflation rather than a means of obfuscating malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:48 AM
Security Audit — agent-trust-hub — abac-access-control