authentication-oauth
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational and advisory tool for implementing secure authentication mechanisms. The instructions explicitly guide the agent to prioritize security best practices like defense-in-depth and secure-by-default configurations.
- [SAFE]: All code examples provided in the patterns follow security industry standards, such as using environment variables for secrets (
process.env.JWT_SECRET), implementing PKCE for OAuth, and utilizing strong hashing algorithms like bcrypt and Argon2. - [SAFE]: The skill references well-known and trusted external services for legitimate security purposes, such as Google's OAuth endpoints and the HaveIBeenPwned API for password breach checks.
- [SAFE]: Detailed descriptions of vulnerabilities (e.g., JWT in localStorage, session fixation) and corresponding detection patterns are provided strictly for the agent's diagnostic and auditing capabilities.
Audit Metadata