backend-authorization

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a highly detailed educational and architectural resource for implementing backend authorization. It does not contain any executable scripts, remote code downloads, or instructions that would bypass safety guidelines.
  • [SAFE]: The skill promotes security best practices, including 'Default Deny', 'Least Privilege', 'Separation of Duties', and 'Defense in Depth' via data-level authorization (RLS).
  • [SAFE]: Implementation examples use well-known, legitimate security libraries and frameworks such as Casbin, OPA, Cerbos, and Permit.io. No suspicious or unverified third-party dependencies were found.
  • [SAFE]: Testing guidelines include comprehensive negative testing, fuzzing for edge cases, and regression testing to ensure authorization logic remains secure during updates.
  • [SAFE]: Emergency access protocols (Break-Glass) and Just-In-Time (JIT) elevation patterns are correctly documented with mandatory logging and automatic expiration to prevent privilege creep.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 08:00 PM
Security Audit — agent-trust-hub — backend-authorization