pachca-custom-properties
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and runs the
@pachca/clipackage from the npm registry usingnpx. This is the official tool provided by the vendor for interacting with their service. - [COMMAND_EXECUTION]: Bash commands are used to configure the environment with an API token and execute the CLI tool for authentication checks and API requests.
- [CREDENTIALS_UNSAFE]: The instructions ask the user to provide an API token to authenticate the CLI. This is a standard and expected authentication flow for this type of integration; no hardcoded credentials or unauthorized data harvesting were found.
Audit Metadata