ping-quickstart

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The documentation in references/runtime/mcp-preflight.md describes the local execution of MCP servers via npx (specifically the @pingidentity scoped package). This is an expected mechanism for initializing agent tools in environments like Claude Code.
  • [DATA_EXPOSURE]: The skill instructions in references/runtime/mcp-preflight.md guide the agent to read and write configuration values within ~/.claude/settings.json. This access is limited to the pluginConfigs specific to the pingidentity author and is used to manage required parameters like tenant URLs and environment IDs.
  • [EXTERNAL_DOWNLOADS]: The skill references several official Ping Identity documentation portals (e.g., docs.pingidentity.com, developer.pingidentity.com) and GitHub repositories (e.g., github.com/ForgeRock/ping-android-sdk). These resources are owned by the vendor or associated with their established infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 12:19 PM
Security Audit — agent-trust-hub — ping-quickstart