codacy-cloud-cli

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official @codacy/codacy-cloud-cli package via the NPM registry. This is a legitimate vendor-owned resource.- [COMMAND_EXECUTION]: The skill uses various shell commands through the codacy CLI to manage repositories, quality metrics, and security findings. These operations are essential for the skill's primary purpose.- [CREDENTIALS_UNSAFE]: The documentation provides standard instructions for authenticating the CLI using an API token and mentions the default storage path for credentials (~/.codacy/credentials). No hardcoded secrets or unsafe exposures were detected.- [DATA_EXFILTRATION]: The skill communicates with official Codacy infrastructure (app.codacy.com) to retrieve and synchronize analysis data. This activity is the intended function of the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:15 PM
Security Audit — agent-trust-hub — codacy-cloud-cli