frontend-auth-flow-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference materials are focused on promoting secure browser-level authentication contracts. It provides checklists for validating redirects, credential handling, and WebAuthn implementations without introducing any dangerous capabilities.
- [SAFE]: The skill correctly identifies security boundaries, instructing the agent to delegate core security tasks like token storage, CSRF, and XSS protection to a separate security-focused skill.
- [SAFE]: All external sources referenced are well-known and trusted organizations, including OWASP, NIST, W3C, and MDN.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or dynamic execution was found across the skill files, reference checklists, or evaluation scenarios.
Audit Metadata