better-auth

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The script scripts/better_auth_init.py acts as a data ingestion surface by prompting users for configuration values (such as database URLs and OAuth credentials) and writing them directly into project files (auth.ts and .env).
  • Ingestion points: Interactive prompts in scripts/better_auth_init.py using the input() function.
  • Boundary markers: Absent; user input is directly interpolated into file templates.
  • Capability inventory: Local filesystem write access via pathlib.Path.write_text() in the _save_files method of BetterAuthInit.
  • Sanitization: Basic stripping of quotes and whitespace is performed, but there is no formal validation or escaping of the input content before it is written to the filesystem.
  • [DATA_EXFILTRATION]: The initialization script scripts/better_auth_init.py programmatically accesses and parses sensitive environment files to load existing project configurations.
  • Evidence: The _load_env_files method in scripts/better_auth_init.py searches for and reads .env files from the project root, .claude/, and .claude/skills/ directories.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:15 AM
Security Audit — agent-trust-hub — better-auth