valyd-integration

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference materials serve as a technical guide for using the Valyd identity and verification platform. It includes detailed best practices for securing integrations, such as the use of server-side markers for CSRF protection and signature verification for webhooks.
  • [SAFE]: All external domains and packages referenced (e.g., idp.valyd.work, dev.valyd.work, and @valyd/sdk) are official resources belonging to the vendor, valyd-id. These resources are documented neutrally as part of the intended platform functionality.
  • [SAFE]: While the documentation contains example credentials and API keys in references/portal-and-accounts.md, these are explicitly identified as balance-capped public demo credentials intended for testing and are accompanied by prominent warnings not to use them in real integrations.
  • [SAFE]: The skill uses industry-standard libraries for security features, such as libsodium-wrappers for end-to-end encryption (E2EE) and standard OAuth 2.1 protocols for authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:14 AM
Security Audit — agent-trust-hub — valyd-integration