Is davidedicillo/codifica safe?
Yes. davidedicillo/codifica is safe to install. Oathe's behavioral security audit gave the codifica skill by davidedicillo a trust score of 87/100 with 3 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/davidedicillo/codifica
Is davidedicillo/codifica safe to install?
Codifica is a legitimate file-based protocol for coordinating work between AI agents and humans using Git repositories. The skill provides extensive but transparent behavioral instructions for task management and git workflows. While it gives significant control over agent behavior and requires reading repository files, no malicious functionality was detected and all security monitoring passed cleanly.
What security issues were found in davidedicillo/codifica?
Category Scores
Findings (3)
MEDIUM Prescriptive Agent Behavior Instructions -15 ▶
The skill provides detailed mandatory instructions for agent behavior including specific file reading requirements, git operations, and workflow rules. While legitimate for task coordination, this represents significant behavioral control over the agent.
LOW Repository File Access Requirements -10 ▶
The protocol requires agents to read various files from repositories (codifica.json, spec files, state files) which could potentially expose sensitive information if present in those files.
LOW Potential for Misuse in Compromised Repositories -20 ▶
While the protocol itself is legitimate, if a repository's codifica.json or spec files were controlled by a malicious actor, they could potentially influence agent behavior beyond intended scope.
Should I install davidedicillo/codifica?
Oathe's verdict for davidedicillo/codifica is SAFE with a trust score of 87/100. Recommendation: Install.