codehealth-mcp
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
@codescene/codehealth-mcppackage from the NPM registry vianpx. This is the standard, documented method for deploying this structural analysis tool. - [COMMAND_EXECUTION]: The agent is configured to use the
npxcommand to run the code health analysis server in the local environment. - [SAFE]: Credential safety is prioritized; the skill uses placeholders for access tokens and provides explicit warnings to users about not committing sensitive tokens to version control.
- [SAFE]: The skill documentation clearly defines the scope of data access, restricting analysis to local repository files and referring users to official upstream privacy and security policies.
Audit Metadata