valyd-integration
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference materials serve as a technical guide for using the Valyd identity and verification platform. It includes detailed best practices for securing integrations, such as the use of server-side markers for CSRF protection and signature verification for webhooks.
- [SAFE]: All external domains and packages referenced (e.g.,
idp.valyd.work,dev.valyd.work, and@valyd/sdk) are official resources belonging to the vendor, valyd-id. These resources are documented neutrally as part of the intended platform functionality. - [SAFE]: While the documentation contains example credentials and API keys in
references/portal-and-accounts.md, these are explicitly identified as balance-capped public demo credentials intended for testing and are accompanied by prominent warnings not to use them in real integrations. - [SAFE]: The skill uses industry-standard libraries for security features, such as
libsodium-wrappersfor end-to-end encryption (E2EE) and standard OAuth 2.1 protocols for authentication.
Audit Metadata