koda-learn

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch remote content from several sources: a GitHub repository (XCode-NLP/KodaSkills), community APIs (agentskill.sh, neuraldeep.ru), and secondary search directories (mcpmarket.com, mcpservers.org, OpenAI, Anthropic).
  • [REMOTE_CODE_EXECUTION]: By design, this skill downloads SKILL.md files (which contain natural language instructions and potentially tool-call definitions) into a local workspace directory (.koda/skills/). While these are instructions for the agent rather than binary code, they modify the agent's runtime behavior, which is a form of instruction-level remote code execution.
  • [SAFE_PRACTICE]: The skill implements significant safety guardrails for a package-manager-style tool. It requires a securityScore of at least 75/100 for the agentskill.sh source, mandates that skills must be 'approved', and requires explicit user confirmation before installing found skills. It also targets its own vendor repository (XCode-NLP) as the primary source.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 08:08 AM
Security Audit — agent-trust-hub — koda-learn