xano-init
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Executes shell commands via the Xano CLI and npm to verify tool availability, check for updates, and manage developer profiles.- [EXTERNAL_DOWNLOADS]: Recommends the installation of official vendor packages (@xano/cli and @xano/developer-mcp) from the well-known npm registry.- [CREDENTIALS_UNSAFE]: Retrieves authentication tokens through the CLI to configure profiles, but includes explicit instructions to the agent to suppress output and avoid exposing tokens to the user.- [PROMPT_INJECTION]: Contains an indirect injection surface where branch names or workspace titles retrieved from the Xano API are written into project documentation files like CLAUDE.md.
Audit Metadata