auth-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to guide agents in implementing secure authentication flows. It explicitly enforces 'Hard Rules' that align with security standards like OWASP and RFC 6749.
  • [COMMAND_EXECUTION]: Includes helper scripts (validate-oauth-scopes.ts and cookie-attribute-checker.ts) designed to be run manually or in CI to audit local code for common auth misconfigurations. These scripts perform deterministic checks on local files and specific URLs provided by the user.
  • [DATA_EXPOSURE]: The skill provides templates and guides for managing credentials but correctly advises the use of environment variables and secret managers rather than hardcoding values. No credential exposure was found.
  • [EXTERNAL_DOWNLOADS]: The skill references numerous official documentation sites and well-known technology organizations (Google, OWASP, Mozilla, Vercel, etc.) as authoritative research sources, which is consistent with its purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:22 AM
Security Audit — agent-trust-hub — auth-weapon