session-cookie-flags

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing best practices for HTTP cookie security based on well-known resources like Frontend Checklist and MDN.
  • [SAFE]: No tools or platform-specific permissions are requested in the configuration, limiting the skill's capability to only text-based interaction and analysis.
  • [SAFE]: Code examples for Next.js, Express.js, and Nginx follow standard security patterns, such as using environment variables for secrets and enabling protection flags in production environments.
  • [SAFE]: External references point to legitimate and well-known security services, including Mozilla Observatory and Frontend Checklist.
  • [SAFE]: Auditing instructions (e.g., using curl) are provided as manual verification steps for the user and are not executed autonomously by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:30 AM
Security Audit — agent-trust-hub — session-cookie-flags