twingate-idfw
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a comprehensive technical guide for the Twingate Identity Firewall. All external references and download links point to official Twingate GitHub repositories (
github.com/Twingate/*,github.com/Twingate-Solutions/*) or official product documentation. These resources are used appropriately to provide current configuration schemas and troubleshooting steps. - [SAFE]: The skill advocates for security best practices, such as recommending HashiCorp Vault for production SSH Certificate Authority management to keep private keys off-disk and providing clear guidance on cryptographically verifying Gateway Access Tokens (JWTs) using ES256 and JWKS endpoints.
- [SAFE]: Instructions for session recording and audit logging emphasize that data remains within the user's infrastructure (emitted to stderr for local collection), which aligns with privacy and compliance standards.
- [SAFE]: Documentation for web app integrations (e.g., Grafana, Jenkins) includes specific security warnings about the risks of trusted-header authentication vs. JWT verification, ensuring users implement these integrations with proper network isolation.
Audit Metadata