codacy-analysis-cli

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @codacy/analysis-cli official package from the NPM registry to enable local analysis.\n- [REMOTE_CODE_EXECUTION]: The CLI provides a mechanism to download and setup standard static analysis tool binaries (such as Ruff, Semgrep, and ESLint) into a dedicated machine-wide directory (~/.codacy/) using the --install-dependencies flag.\n- [COMMAND_EXECUTION]: Orchestrates the execution of various static analysis tools on the local filesystem to detect bugs, security issues, and linting violations.\n- [CREDENTIALS_UNSAFE]: Documents the optional use of API tokens and the vendor-specific credential file ~/.codacy/credentials for synchronizing configurations with the Codacy platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:15 PM
Security Audit — agent-trust-hub — codacy-analysis-cli