koda-vscode-helper

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches information from official GitHub repositories and documentation websites for Microsoft VS Code, VSCodium, and Eclipse Theia. These are well-known and trusted sources.
  • [COMMAND_EXECUTION]: The skill instructions mention using tools like fetch_url_content to retrieve information from documentation sites. This is a standard and appropriate use for a documentation assistant.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as GitHub issue trackers. While this is an ingestion surface for potentially untrusted content, the risk is minimized by the use of official repositories.
  • Ingestion points: Official GitHub repositories for VS Code, VSCodium, and Theia.
  • Boundary markers: None.
  • Capability inventory: Read-only access to external URLs using standard fetching tools.
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 08:10 AM
Security Audit — agent-trust-hub — koda-vscode-helper