82OUT OF 100
Likely safeLikely safeStatic read

kodelyx/flow-agent

The repository is a well-documented CLI toolkit for Google Flow. The static analysis shows no malicious behavior. All flagged network references are either documentation of local loopback addresses (127.0.0.1/0.0.0.0) for inter-process communication or standard, documented provisioning steps (uv installation). The code aligns perfectly with the declared intent in the README. No malicious behavior observed in our static read; full runtime behavior was not executed in a sandbox on this pass.

Repository size
363 KB
Packages
0
Stars
51
Created
376 days ago
Reputation signals
kodelyx avatar
Akash Yadav
@kodelyx
Account age1 yr
Public repos11
Forks25
Community sentiment85

Positive

Code & behavior signals
Local loopback communication
LowCode

The application uses 127.0.0.1 and 0.0.0.0 for local inter-process communication between the CLI, the Chrome extension, and the backend service, which is consistent with the project's architecture.

External dependency provisioning
LowBehavior

The setup script fetches 'uv' from astral.sh, a recognized and standard tool for Python environment management, as documented in the README.

Per-package scoring
Final verdict

No malicious behavior in our static read. The caveats above are worth noting and the owner is not yet long-established. Runtime was not executed in a sandbox on this pass.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Cloned repository kodelyx/flow-agent at commit e7f64ae.
Static scan
›Scanned 15 files.
›No obfuscation, hardcoded credentials, or malicious install hooks detected.
Reputation
›Owner 'kodelyx' is established with 11 repositories and positive community engagement.
Read
›Verified README intent against code behavior.
›Confirmed all network references are local loopback or documented tool installation.
Score
›Score computed by formula: 82/100 (deterministic, code-driven)
›-6 [code] network: Code has outbound network capability (fetch / child_process / hardcoded IP URL).
›-6 [code] model_findings: 2 code/behavior finding(s) reported by the read model.
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+4 [reputation] good_sentiment: Positive community sentiment (85/100).
Auto-published at clauderabbit.in/kodelyx/flow-agent · re-checked when the repo changes