rivetkit

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The documentation includes numerous command-line examples for users to set up their development and production environments. These include installing dependencies (npm install), running containers (docker run), managing systemd services (systemctl), and deploying via CLI tools (gcloud, wrangler, railway). All instances are standard developer operations and are documented safely.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for fetching the rivetkit library and associated tools (like hono, vitest, and drizzle-orm) from the official npm registry. It also references official Rivet documentation and GitHub repositories for templates and examples.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly addresses secret management, using non-functional placeholders (e.g., sk_xxxxx, pk_xxxxx, YOUR_RIVET_TOKEN) in all examples. It correctly guides users to use environment variables for sensitive data and distinguishes between secret and publishable tokens.
  • [PROMPT_INJECTION]: There are no instructions that attempt to override agent behavior, bypass safety guardrails, or manipulate system prompts.
  • [DATA_EXFILTRATION]: The skill does not contain any code or instructions that would result in the unauthorized transmission of sensitive data from the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides specific security guidance to developers on how to avoid injection vulnerabilities in their own applications, such as using array-based compound keys to sanitize user-provided data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — rivetkit