backend-doctor

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its described diagnostic purpose, focusing on local code inspection and testing without any evidence of malicious intent or unauthorized access.
  • [COMMAND_EXECUTION]: The skill executes development lifecycle commands (e.g., npm test, pytest, go test) and diagnostic tools (e.g., lsp_diagnostics, grep) that are dynamically identified from the local project's manifest files.
  • [CREDENTIALS_UNSAFE]: Included in the health check is a scan for hardcoded secrets, API keys, and passwords within the source code to identify exposure risks for reporting and remediation.
  • [EXTERNAL_DOWNLOADS]: Uses curl for internal health probes against localhost and invokes standard dependency audit tools that interact with trusted package registries (NPM, PyPI, Maven) to check for known vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 10:46 AM
Security Audit — agent-trust-hub — backend-doctor