session-cookie-flags
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing best practices for HTTP cookie security based on well-known resources like Frontend Checklist and MDN.
- [SAFE]: No tools or platform-specific permissions are requested in the configuration, limiting the skill's capability to only text-based interaction and analysis.
- [SAFE]: Code examples for Next.js, Express.js, and Nginx follow standard security patterns, such as using environment variables for secrets and enabling protection flags in production environments.
- [SAFE]: External references point to legitimate and well-known security services, including Mozilla Observatory and Frontend Checklist.
- [SAFE]: Auditing instructions (e.g., using
curl) are provided as manual verification steps for the user and are not executed autonomously by the skill.
Audit Metadata