skills/picahq/skills/pica-langchain/Gen Agent Trust Hub

pica-langchain

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Spawns a local subprocess using npx @picahq/mcp to provide tool capabilities via the Model Context Protocol using stdio transport. This is the standard delivery method for the vendor's MCP server.
  • [EXTERNAL_DOWNLOADS]: References official packages from the vendor (@picahq/mcp) and trusted organizations including langchain-ai and anthropics. These are well-known, reputable sources for AI development.
  • [CREDENTIALS_UNSAFE]: Explicitly recommends using environment variables for the PICA_SECRET and provides clear instructions on avoiding hardcoded credentials by using .env files.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 11:31 AM