better-auth
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official Better Auth ecosystem packages (e.g.,
@better-auth/cli,@better-auth/expo,@better-auth/oauth-provider) and suggests using standard package managers to install them. These references target the project's own infrastructure and are considered safe practice. - [COMMAND_EXECUTION]: The instructions include standard developer CLI commands such as
npx @better-auth/cli generatefor schema synchronization andopenssl rand -base64 32for generating encryption secrets. These are legitimate operations for the stated purpose of auth framework management. - [INDIRECT_PROMPT_INJECTION]: The skill provides documentation on handling untrusted data (user credentials, OAuth responses, and multi-tenant invitations). It correctly instructs on the implementation of security boundaries, including CSRF protection via trusted origins, Fetch Metadata validation, and secure cookie attributes. It also details the use of hashing (scrypt/argon2) and cryptographically random tokens for sensitive operations.
- [PRIVILEGE_ESCALATION]: While the skill mentions an 'admin' plugin and RBAC, these are documented as application-level logic for user management (e.g.,
user.role === 'admin') rather than system-level privilege escalation attempts.
Audit Metadata