dynamic

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides an init action that automates project scaffolding, including the creation of directory structures and configuration files for Next.js and the bkend.ai platform.
  • [REMOTE_CODE_EXECUTION]: Configures an MCP server using the @bkend/mcp-server package via the Node.js package runner (npx) as part of the intended platform integration.
  • [CREDENTIALS_UNSAFE]: Uses environment variable placeholders such as NEXT_PUBLIC_BKEND_API_KEY and BKEND_PROJECT_ID within code templates and configuration files, which is the recommended practice for secure secret handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:43 PM
Security Audit — agent-trust-hub — dynamic