descope-byos-builder
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill does not contain any malicious code, obfuscation, or data exfiltration attempts. It provides technical guidance for integrating with a known authentication provider.
- [COMMAND_EXECUTION]: Includes a local script,
parse-flow.mjs, which the agent is instructed to run for analyzing flow configuration JSONs provided by the user. The script only performs static data parsing. - [EXTERNAL_DOWNLOADS]: Recommends the use of legitimate packages such as
@descope/react-sdkand@tanstack/react-queryfor the final application implementation. - [PROMPT_INJECTION]: The skill explicitly instructs the agent to request necessary data from the user rather than attempting to access external environments or credentials autonomously.
Audit Metadata