frevana-auth

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash script to execute frevana login and npm install commands to manage the CLI lifecycle and authentication state.\n- [EXTERNAL_DOWNLOADS]: The skill is configured to download the @frevana/frevana package from the global npm registry if the local command is unavailable.\n- [CREDENTIALS_UNSAFE]: The skill checks the file path ~/.frevana/cli-config.json to confirm that credentials have been successfully stored locally. The instructions include specific guidance to treat this information as sensitive and avoid echoing the API key to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 12:27 AM
Security Audit — agent-trust-hub — frevana-auth