puck
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates strong security hygiene by explicitly instructing the agent never to ask for API keys in chat, instead directing users to use local environment variables.
- [SAFE]: Multiple reference files (ai.md, integration.md, troubleshooting.md) emphasize the necessity of implementing application-level authentication for editor routes and save endpoints to prevent unauthorized access or resource abuse.
- [SAFE]: All tool usage and external references are limited to official vendor domains (puckeditor.com) and the official @puckeditor namespace on NPM.
- [SAFE]: The skill promotes developer best practices by advising against bypassing standard security protocols or using generic blocks that could lead to unvetted code execution.
Audit Metadata