cors-api-proxy

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based and does not contain any executable scripts, tools, or automated commands. It describes an architectural pattern for 'Scoped API Token Proxy' to handle Looker API authentication securely.\n- [DATA_EXPOSURE]: The skill correctly identifies the 'Browser Secret Problem' and provides instructions to ensure API secrets remain on the server. It recommends using .env files for local development, which is consistent with standard secret management practices for the described pattern.\n- [EXTERNAL_DOWNLOADS]: While the reference documentation mentions npm install, it does not list specific external dependencies or execute remote code. It provides instructions for a user to set up a local development environment manually.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 12:22 AM