authentication-failures

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of best practices and coding guidelines for improving authentication security in FastAPI and Flask applications. It demonstrates how to implement secure JWT handling, rate limiting, and password validation.
  • [EXTERNAL_DOWNLOADS]: The skill references the HaveIBeenPwned API (api.pwnedpasswords.com) for breached-password checking. This is a well-known security service used for defensive purposes and is considered safe within this context.
  • [COMMAND_EXECUTION]: Provides standard security linting and auditing commands using common tools like bandit, pip-audit, and safety. These are legitimate developer tools for static analysis and dependency checking.
  • [PROMPT_INJECTION]: The system instructions define triggers for the skill based on user requests related to authentication security, which is standard behavior for an AI agent skill and does not attempt to override core safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:13 PM
Security Audit — agent-trust-hub — authentication-failures