google-signin
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides security-hardened implementation guidance for Google Sign-In, including mandatory checklists for token verification and CSRF protection.
- [EXTERNAL_DOWNLOADS]: References the official Google Identity Services client script from https://accounts.google.com/gsi/client. This is a standard and safe reference to a well-known service.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found; the skill uses placeholders and explicitly recommends against storing the Google client secret in the application.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns from unknown sources were identified. The use of official Google libraries for token verification is a standard security practice.
Audit Metadata