pubnub-keyset-management

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill is designed to improve developer security by providing guidelines for key rotation, environment separation, and credential hygiene.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive tokens were found. The skill includes explicit instructions and templates (such as the git pre-commit hook) specifically designed to detect and block the accidental commitment of PubNub keys (pub-c-, sub-c-, sec-c-).
  • [PROMPT_INJECTION]: No attempts to bypass safety filters or override agent behavior were detected. The instructions prioritize standard security protocols for managing real-time infrastructure.
  • [REMOTE_CODE_EXECUTION]: No suspicious remote code execution or untrusted download patterns were identified. Mentions of command execution (e.g., git diff, child_process.execSync) are limited to local developer tools and pre-commit hooks intended to be run by the user for security auditing.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized data access patterns were found. The skill correctly identifies the 'Secret Key' as a server-side only asset and provides patterns for retrieving it securely from environment variables or secrets managers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 12:42 PM
Security Audit — agent-trust-hub — pubnub-keyset-management