navan-security-basics
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill advocates for industry-standard security practices, including the use of environment variables for sensitive credential storage and the correct implementation of
.gitignoreto prevent credential leakage in version control. - [SAFE]: Network operations are scoped to legitimate, official vendor domains (
api.navan.comandnavan.com) for intended functional purposes such as OAuth 2.0 token exchange and SCIM provisioning tests. - [SAFE]: No obfuscation, hardcoded credentials, or suspicious remote script execution patterns were identified. All script examples provided are transparent and serve educational or integration-hardening purposes.
Audit Metadata