openwa
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely informational and serves as a technical reference for the OpenWA platform. It contains no executable code or malicious instructions.
- [SAFE]: Authentication mechanisms are documented using placeholders (e.g., 'owa_k1_xxxxxxxx...') and clearly explain the security implications of development-mode defaults like the 'dev-admin-key'.
- [SAFE]: Network operations described (fetch, curl, Socket.IO) are standard integration examples for interacting with the local or self-hosted API gateway.
- [SAFE]: Deployment instructions for Docker and Kubernetes follow standard practices, including health check definitions and volume management advice.
- [SAFE]: The 'Gotchas' section proactively warns users about potential security pitfalls, such as the dangers of 'synchronize: true' in production databases and the permissive nature of default CORS settings.
Audit Metadata