aixyz-on-openclaw

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the installation script for the Bun runtime from the official well-known domain bun.sh.
  • [COMMAND_EXECUTION]: Executes the downloaded Bun installation script via shell piping (bash on Unix/macOS or iex on Windows).
  • [COMMAND_EXECUTION]: Utilizes bunx (Bun's package runner) to execute the create-aixyz-app scaffolding tool to set up project structures.
  • [EXTERNAL_DOWNLOADS]: Instructions include downloading the use-agently skill from the vendor's official GitHub repository (github.com/agentlyhq/use-agently).
  • [COMMAND_EXECUTION]: Mentions using npx ngrok for local tunnel testing, which is a standard developer practice for testing webhooks and connectivity.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 12:53 PM