cors-api-proxy
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely documentation-based and does not contain any executable scripts, tools, or automated commands. It describes an architectural pattern for 'Scoped API Token Proxy' to handle Looker API authentication securely.\n- [DATA_EXPOSURE]: The skill correctly identifies the 'Browser Secret Problem' and provides instructions to ensure API secrets remain on the server. It recommends using
.envfiles for local development, which is consistent with standard secret management practices for the described pattern.\n- [EXTERNAL_DOWNLOADS]: While the reference documentation mentionsnpm install, it does not list specific external dependencies or execute remote code. It provides instructions for a user to set up a local development environment manually.
Audit Metadata