xai-grok-onboarding

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a standard RFC 8628 Device Authorization Grant to facilitate xAI account connection, relying on the official xAI OAuth infrastructure.
  • [SAFE]: Security-conscious credential management is evident, including the use of restricted file permissions (0o600) for local state files and explicit instructions to the agent to avoid logging or echoing persistent access or refresh tokens.
  • [SAFE]: Internal platform communication is handled securely via localhost requests for cache management, adhering to expected platform integration patterns.
  • [SAFE]: The skill utilizes a platform-provided backend module (core.xai_grok) rather than downloading or installing unverified external dependencies at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:46 PM
Security Audit — agent-trust-hub — xai-grok-onboarding