skills/pachca/openapi/pachca-oauth/Gen Agent Trust Hub

pachca-oauth

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx -y @pachca/cli to download and execute the vendor's official command-line interface from the NPM registry. This is a standard method for accessing utility tools.
  • [COMMAND_EXECUTION]: The instructions utilize the Bash tool to run CLI commands for checking authentication status and retrieving token information. These operations are consistent with the skill's stated purpose of providing OAuth metadata.
  • [CREDENTIALS_UNSAFE]: The skill guides the user on providing a PACHCA_TOKEN via environment variables or command flags. It does not contain hardcoded credentials and uses standard practices for handling API tokens within a CLI environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 11:11 AM
Security Audit — agent-trust-hub — pachca-oauth