pachca-custom-properties

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and runs the @pachca/cli package from the npm registry using npx. This is the official tool provided by the vendor for interacting with their service.
  • [COMMAND_EXECUTION]: Bash commands are used to configure the environment with an API token and execute the CLI tool for authentication checks and API requests.
  • [CREDENTIALS_UNSAFE]: The instructions ask the user to provide an API token to authenticate the CLI. This is a standard and expected authentication flow for this type of integration; no hardcoded credentials or unauthorized data harvesting were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 01:59 PM
Security Audit — agent-trust-hub — pachca-custom-properties