password-field-security

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference implementation for checking password breaches via the well-known Pwned Passwords API (api.pwnedpasswords.com). This implementation follows the privacy-preserving k-anonymity protocol, sending only a partial hash prefix to the service.- [DATA_EXFILTRATION]: No unauthorized data transmission or access to sensitive environment credentials (such as .env or .ssh files) was detected. The network communication is limited to a reputable third-party security service for its intended purpose.- [PROMPT_INJECTION]: The instructions are strictly limited to code review and security auditing tasks, with no evidence of attempts to override agent behavior, bypass safety filters, or extract system prompts.- [SAFE]: All provided code examples for React, TypeScript, and HTML adhere to industry-standard best practices for secure and accessible frontend development. The skill aims to improve application security through proper input handling and validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:30 AM
Security Audit — agent-trust-hub — password-field-security