c456-cli
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxandbunxto execute thec456-clipackage and provides instructions to install the skill directly from the author's GitHub repository (xiaohui-zhangxh/c456-cli). These resources are consistent with the vendor's identity. - [COMMAND_EXECUTION]: The agent is instructed to execute various subcommands of the
c456CLI to manage data (intakes, playbooks) and fetch content from external URLs (c456 fetch). - [CREDENTIALS_UNSAFE]: The skill documents the use of
C456_API_KEYfor authentication and provides a command to set the key (c456 config set-key). It includes a specific safety guideline instructing the agent not to display the full API key in logs or user responses.
Audit Metadata