api-auth-key-management

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides detailed guidance on implementing secure API key management systems based on industry benchmarks (OWASP API Security Top 10) and compliance standards (SOC 2, PCI-DSS 4.0). It recommends secure practices such as using high-entropy keys with checksums, irretrievable hashing (SHA-256), and zero-downtime rotation workflows.
  • [SAFE]: References to external entities (GitHub, AWS, Stripe, Anthropic, OpenAI) are used neutrally as examples of industry-standard security implementations. The skill includes links to official documentation for secret scanning and rotation mechanics, which are well-known and trusted services.
  • [SAFE]: The skill references other components within the same vendor's library (samber/developer-platform-skills). These are internal architectural references and do not represent cross-vendor privilege escalation or unauthorized access.
  • [SAFE]: No malicious patterns such as prompt injection, code obfuscation, data exfiltration, or persistence mechanisms were found. The skill is purely instructional and does not invoke tools, execute scripts, or perform network operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — api-auth-key-management