backend-doctor
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's behavior is consistent with its described diagnostic purpose, focusing on local code inspection and testing without any evidence of malicious intent or unauthorized access.
- [COMMAND_EXECUTION]: The skill executes development lifecycle commands (e.g., npm test, pytest, go test) and diagnostic tools (e.g., lsp_diagnostics, grep) that are dynamically identified from the local project's manifest files.
- [CREDENTIALS_UNSAFE]: Included in the health check is a scan for hardcoded secrets, API keys, and passwords within the source code to identify exposure risks for reporting and remediation.
- [EXTERNAL_DOWNLOADS]: Uses curl for internal health probes against localhost and invokes standard dependency audit tools that interact with trusted package registries (NPM, PyPI, Maven) to check for known vulnerabilities.
Audit Metadata