kody — autonomous development engine. Single-session Claude Code agent behind a generic executor + declarative implementation profiles.
When the engine runs in GitHub Actions, it can copy declared runner secrets to the package's remote dashboard if its vault lookup falls back to environment values. This is credential export during normal runtime, not install time.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/bin/kody.jsView on unpkg · L11This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/kody.jsView on unpkgPackage source references child process execution.
dist/bin/kody.jsView on unpkg · L1238A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/kody.jsView on unpkg · L4174Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/kody.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/bin/kody.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/kody.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/kody.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
dist/runtime-services/goal-scheduler/scheduler.shView on unpkgThis report applies to @kody-ade/kody-engine@0.4.634.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/bin/kody.jsView on unpkg · L11This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin/kody.jsView on unpkgPackage source references child process execution.
dist/bin/kody.jsView on unpkg · L1238A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bin/kody.jsView on unpkg · L4174Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/kody.jsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/bin/kody.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/kody.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/bin/kody.jsView on unpkg · L11Package ships non-JavaScript build or shell helper files.
dist/runtime-services/goal-scheduler/scheduler.shView on unpkg