rivetkit
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The documentation includes numerous command-line examples for users to set up their development and production environments. These include installing dependencies (
npm install), running containers (docker run), managing systemd services (systemctl), and deploying via CLI tools (gcloud,wrangler,railway). All instances are standard developer operations and are documented safely. - [EXTERNAL_DOWNLOADS]: The skill provides instructions for fetching the
rivetkitlibrary and associated tools (likehono,vitest, anddrizzle-orm) from the official npm registry. It also references official Rivet documentation and GitHub repositories for templates and examples. - [CREDENTIALS_UNSAFE]: The documentation explicitly addresses secret management, using non-functional placeholders (e.g.,
sk_xxxxx,pk_xxxxx,YOUR_RIVET_TOKEN) in all examples. It correctly guides users to use environment variables for sensitive data and distinguishes between secret and publishable tokens. - [PROMPT_INJECTION]: There are no instructions that attempt to override agent behavior, bypass safety guardrails, or manipulate system prompts.
- [DATA_EXFILTRATION]: The skill does not contain any code or instructions that would result in the unauthorized transmission of sensitive data from the agent's environment.
- [INDIRECT_PROMPT_INJECTION]: The skill provides specific security guidance to developers on how to avoid injection vulnerabilities in their own applications, such as using array-based compound keys to sanitize user-provided data.
Audit Metadata