configure-codacy

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the 'codacy' and 'codacy-analysis' CLI tools to perform repository initialization, execute local static analysis, and synchronize settings with the cloud.
  • [EXTERNAL_DOWNLOADS]: The skill recommends performing dependency installation using 'npm install' when configuring ESLint and uses CLI flags that automate dependency resolution during analysis.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by instructing the agent to process repository contents and tool outputs to generate tuning suggestions. Ingestion points: local repository source code and 'codacy-analysis' JSON output. Boundary markers: none. Capability inventory: shell command execution and configuration file modification. Sanitization: the skill contains a mandatory instruction to never disable patterns in the 'Security' category.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:15 PM
Security Audit — agent-trust-hub — configure-codacy