xano-init

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Executes shell commands via the Xano CLI and npm to verify tool availability, check for updates, and manage developer profiles.- [EXTERNAL_DOWNLOADS]: Recommends the installation of official vendor packages (@xano/cli and @xano/developer-mcp) from the well-known npm registry.- [CREDENTIALS_UNSAFE]: Retrieves authentication tokens through the CLI to configure profiles, but includes explicit instructions to the agent to suppress output and avoid exposing tokens to the user.- [PROMPT_INJECTION]: Contains an indirect injection surface where branch names or workspace titles retrieved from the Xano API are written into project documentation files like CLAUDE.md.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 06:42 PM