skills/affaan-m/ecc/codehealth-mcp/Gen Agent Trust Hub

codehealth-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the @codescene/codehealth-mcp package from the NPM registry via npx. This is the standard, documented method for deploying this structural analysis tool.
  • [COMMAND_EXECUTION]: The agent is configured to use the npx command to run the code health analysis server in the local environment.
  • [SAFE]: Credential safety is prioritized; the skill uses placeholders for access tokens and provides explicit warnings to users about not committing sensitive tokens to version control.
  • [SAFE]: The skill documentation clearly defines the scope of data access, restricting analysis to local repository files and referring users to official upstream privacy and security policies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — codehealth-mcp