canary-token-system
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill describes a legitimate security monitoring workflow for managing canary tokens.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill mentions the intentional use of fake secrets for honeypot purposes and references environment variables for notification webhooks. These are standard practices for honeypot systems and secure secret management; no evidence of real data harvesting or exfiltration was found.
- [INDIRECT_PROMPT_INJECTION]: While the system described is designed to process data from external automated scanners, the documentation explicitly recommends using HTML escaping in the notification logic to prevent injection attacks.
Audit Metadata