codehealth-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration instructs the agent to use
npx -y @codescene/codehealth-mcpto install and run the MCP server. This involves fetching code from the public NPM registry at runtime. - [REMOTE_CODE_EXECUTION]: The execution of the
@codescene/codehealth-mcppackage vianpxconstitutes remote code execution of a third-party package. While this is the primary mechanism for the skill's functionality, it relies on the integrity of the upstream package hosted on NPM. - [PROMPT_INJECTION]: The skill processes untrusted data by analyzing local source code files through tools like
code_health_reviewandcode_health_score. Malicious instructions embedded in code comments or file metadata within the project being analyzed could potentially influence the agent's behavior (Indirect Prompt Injection). The instructions do not provide explicit boundary markers or sanitization steps for the agent when interpreting these results.
Audit Metadata