workos-to-descope
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill automates the migrating of B2B authentication features, including SSO, SCIM, and RBAC. It utilizes standard command-line tools like
grepfor local codebase analysis and uses the vendor's official MCP server for SDK documentation lookups. - [SAFE]: Access to sensitive files like
.envand project configuration files is restricted to local scanning for the purpose of identifying and replacing service credentials. No unauthorized data exfiltration or credential exposure was detected. - [SAFE]: The skill guides the user through a structured migrating process (Part 1: MCP Check, Part 2: Migration Plan, Part 3: Execution) and enforces human-in-the-loop validation via the
MIGRATION-PLAN.mdfile before any code changes are applied. - [SAFE]: Remote resources referenced, such as the Descope Console and GitHub repositories, are verified vendor assets. The skill follows best practices by recommending no-code alternatives (Flows and Widgets) for management UI, reducing the attack surface in the final application.
Audit Metadata