better-auth
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The script
scripts/better_auth_init.pyacts as a data ingestion surface by prompting users for configuration values (such as database URLs and OAuth credentials) and writing them directly into project files (auth.tsand.env). - Ingestion points: Interactive prompts in
scripts/better_auth_init.pyusing theinput()function. - Boundary markers: Absent; user input is directly interpolated into file templates.
- Capability inventory: Local filesystem write access via
pathlib.Path.write_text()in the_save_filesmethod ofBetterAuthInit. - Sanitization: Basic stripping of quotes and whitespace is performed, but there is no formal validation or escaping of the input content before it is written to the filesystem.
- [DATA_EXFILTRATION]: The initialization script
scripts/better_auth_init.pyprogrammatically accesses and parses sensitive environment files to load existing project configurations. - Evidence: The
_load_env_filesmethod inscripts/better_auth_init.pysearches for and reads.envfiles from the project root,.claude/, and.claude/skills/directories.
Audit Metadata