detect-credential-stuffing-okta
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate security analysis on Okta authentication events to detect 'many failures followed by success' patterns. All operations are local and involve standard JSON processing.
- [DATA_EXPOSURE]: No hardcoded credentials, sensitive file access (like .ssh or .env), or unauthorized network operations were found. The script correctly uses standard input/output for data flow.
- [REMOTE_CODE_EXECUTION]: The script does not use functions like eval() or exec() on untrusted data, nor does it perform remote downloads or piped shell executions. It references sibling scripts for data ingestion in the documentation, which is consistent with the stated repository structure.
- [PROMPT_INJECTION]: The markdown instructions and code comments do not contain instructions to override agent behavior, bypass safety filters, or reveal system prompts.
- [OBFUSCATION]: Analysis of the code and metadata revealed no Base64-encoded payloads, zero-width characters, homoglyphs, or other techniques used to hide malicious intent.
- [COMMAND_EXECUTION]: The skill utilizes argparse for command-line interaction but does not spawn subprocesses or execute arbitrary shell commands based on user input.
Audit Metadata