auth-architect
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is purely instructional and contains no executable code, scripts, or binary files.
- [SAFE]: It promotes established industry security standards, such as OAuth2 with PKCE, OpenID Connect (OIDC), and asymmetric JWT signing (RS256/ES256).
- [SAFE]: The 'Safety Rails' section explicitly identifies and prohibits insecure practices, such as shared secrets for HS256, storing PII/secrets in JWT payloads, and disabling authentication without a plan.
- [SAFE]: No network exfiltration, credential harvesting, or prompt injection patterns were identified in the instructions or reference materials.
Audit Metadata