Kedro Security Review
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
Run a security scan on the kedro-plugins codebase or a pull request.
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .claude/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .claude/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .agents/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .agents/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .cursor/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .cursor/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kedro-org/kedro-plugins.git --path .agents/skills/kedro-plugins-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .gemini/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .gemini/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .github/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .github/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .opencode/skills/kedro-plugins-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kedro-plugins-security-review" agent skill from https://github.com/kedro-org/kedro-plugins/tree/main/.agents/skills/kedro-plugins-security-review into .opencode/skills/kedro-plugins-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kedro-plugins-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kedro-plugins-security-reviewRun a security scan on the kedro-plugins codebase or a pull request.
Kedro Plugins Security Review is an agent skill from kedro-org/kedro-plugins. Run a security scan on the kedro-plugins codebase or a pull request. This skill runs Semgrep with dataset-specific rules, triages findings against the dataset trust model, audits nosec suppressions, and produces one final report. Use when the user says things like "run security scan on the full codebase" or "run security scan on this PR". Produce one final report only, in chat by default or posted to GitHub when explicitly asked.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `reference.md` and `rules/kedro-plugins-security-patterns.yml`).
It sits in Security, covering Security review and Static analysis and SAST. It works with Semgrep and GitHub. The repository describes itself as: First-party plugins maintained by the Kedro team. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ff0b268. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghuvbashuvxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, uv and uvx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kedro Plugins Security Review loads about 3.1k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 1,128 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kedro-org/kedro-plugins at commit ff0b268, republished under its Apache-2.0 licence (© kedro-org). 1,128 words, ~3,142 tokens.
.claude/skills/kedro-plugins-security-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Before scanning, decide two things:
## Mode selection)## Delivery modes)Then run the numbered Workflow below:
mktemp -dreference.mdRead these before triaging findings:
semgrepuvx --from semgrep semgrepuv tool run --from semgrep semgrepp/security-auditp/secretsp/python.agents/skills/kedro-plugins-security-review/rules/kedro-plugins-security-patterns.ymltests/, docs/, and features/ are nested under each plugin directory
(e.g. kedro-datasets/tests/). Use glob patterns that match at any depth:--exclude '**/tests/**'--exclude '**/docs/**'--exclude '**/features/**'--exclude '.agents/'--exclude 'tools/'--exclude '**/kedro_datasets_benchmarks/**'mktemp -dAlways use --metrics=off.
If a uvx or uv tool run Semgrep command fails with a permissions error on a
~/.cache/uv path, ask the user for permission to run outside the sandbox
(i.e. with full filesystem access) and then rerun the same command. Do not
treat a cache permission failure as a real scan failure.
Later workflow steps that invoke Semgrep should refer back to this note instead of repeating it.
Default mode. Show one final report in chat and do not expose intermediate scan output.
Only use when the user explicitly asks to post, submit, or publish the scan result to GitHub.
Post mode is only valid in PR mode — it produces a GitHub PR review payload and there is no PR to attach it to in full-codebase mode. If a user asks to post a full-codebase scan, fall back to chat mode and tell the user why.
In post mode:
Do not post partial results or progress updates.
Use when the user asks to scan the repo, codebase, project, or current branch without narrowing to a PR.
Target:
kedro-datasets/ by default (this is where all dataset code lives)kedro-docker),
scan that directory instead — but note that the triage guidance and manual
review checks are designed for dataset code and may not applyUse when the user asks to scan a PR or when the request names a PR number or URL.
Resolve the PR from:
gh pr viewThen get the changed files:
gh pr diff <number> --name-onlyOnly keep files that still exist in the working tree. Scan just those files.
If the PR has no scannable files, report that clearly and stop.
if command -v semgrep >/dev/null 2>&1; then
ENGINE_LABEL="Semgrep OSS (host CLI)"
SEMGREP_CMD=(semgrep)
elif command -v uvx >/dev/null 2>&1; then
ENGINE_LABEL="Semgrep OSS (uvx)"
SEMGREP_CMD=(uvx --from semgrep semgrep)
elif command -v uv >/dev/null 2>&1; then
ENGINE_LABEL="Semgrep OSS (uv tool run)"
SEMGREP_CMD=(uv tool run --from semgrep semgrep)
else
echo "ERROR: neither semgrep, uvx, nor uv is available."
exit 1
fi
SEMGREP_EXCLUDE=(
--exclude '**/tests/**'
--exclude '**/docs/**'
--exclude '**/features/**'
--exclude '.agents/'
--exclude 'tools/'
--exclude '**/kedro_datasets_benchmarks/**'
)
"${SEMGREP_CMD[@]}" --versionIf the version check fails, apply the Runtime note above before treating the scan as failed.
Check whether the user explicitly asked to keep artifacts before emitting the script below.
If NOT keeping artifacts:
OUTPUT_DIR="$(mktemp -d "${TMPDIR:-/tmp}/kedro-plugins-security-review.XXXXXX")"
cleanup() {
rm -rf "$OUTPUT_DIR"
}
trap cleanup EXIT
mkdir -p "$OUTPUT_DIR/raw"If keeping artifacts (omit the trap entirely):
OUTPUT_DIR="$(mktemp -d "${TMPDIR:-/tmp}/kedro-plugins-security-review.XXXXXX")"
mkdir -p "$OUTPUT_DIR/raw"In that case, report $OUTPUT_DIR at the end of the scan so the user can
inspect it.
For full codebase mode:
SCAN_TARGETS=(kedro-datasets/)
TARGET_LABEL="kedro-datasets (full codebase)"For PR mode:
PR_NUMBER="<resolved-pr-number>"
# Apply the same path exclusions as full-codebase mode.
# Semgrep's --exclude only filters during directory walk, so explicit file
# arguments would otherwise bypass the exclusion list.
# This is a monorepo — excluded dirs are nested (e.g. kedro-datasets/tests/).
# Use contains-style matching, not prefix matching.
SCAN_TARGETS=()
while IFS= read -r path; do
[ -f "$path" ] || continue
skip=0
for segment in /tests/ /docs/ /features/ /kedro_datasets_benchmarks/; do
[[ "/$path" == *"$segment"* ]] && skip=1 && break
done
[[ "$path" == .agents/* ]] && skip=1
[[ "$path" == tools/* ]] && skip=1
(( skip == 0 )) && SCAN_TARGETS+=("$path")
done < <(gh pr diff "$PR_NUMBER" --name-only)
TARGET_LABEL="PR #$PR_NUMBER"If SCAN_TARGETS is empty, stop and report that there are no scannable files
(this also happens when a PR only touches excluded paths like tests/ or
docs/).
Set:
LOCAL_RULESET="$(pwd)/.agents/skills/kedro-plugins-security-review/rules/kedro-plugins-security-patterns.yml"Run these in parallel (each command includes "${SEMGREP_EXCLUDE[@]}"):
(
"${SEMGREP_CMD[@]}" scan --metrics=off \
"${SEMGREP_EXCLUDE[@]}" \
--config p/security-audit \
--json --output "$OUTPUT_DIR/raw/security-audit.json" \
"${SCAN_TARGETS[@]}"
) &
(
"${SEMGREP_CMD[@]}" scan --metrics=off \
"${SEMGREP_EXCLUDE[@]}" \
--config p/secrets \
--json --output "$OUTPUT_DIR/raw/secrets.json" \
"${SCAN_TARGETS[@]}"
) &
(
"${SEMGREP_CMD[@]}" scan --metrics=off \
"${SEMGREP_EXCLUDE[@]}" \
--include="*.py" --config p/python \
--json --output "$OUTPUT_DIR/raw/python.json" \
"${SCAN_TARGETS[@]}"
) &
(
"${SEMGREP_CMD[@]}" scan --metrics=off \
"${SEMGREP_EXCLUDE[@]}" \
--include="*.py" \
--config "$LOCAL_RULESET" \
--json --output "$OUTPUT_DIR/raw/kedro-plugins-security-patterns.json" \
"${SCAN_TARGETS[@]}"
) &
waitIf one or more rulesets fail, continue with the findings from the rulesets that did succeed. Do not abort the full scan. In the final report, include a "Scan errors" section that lists each failed ruleset and its error message so the user knows the scan was partial.
If a scan command fails, apply the Runtime note before marking that ruleset as failed.
Read all JSON files in $OUTPUT_DIR/raw/ directly. Deduplicate by
(check_id, path, start.line) — if the same finding appears in more than one
ruleset output, count it once.
For every unique finding:
reference.mdUse these buckets:
dataset_vulnerabilityby_design_with_documentationneeds_manual_reviewAfter triaging Semgrep output, run the Manual review checks from
reference.md against the scan target.
For each check:
dataset_vulnerability or needs_manual_reviewWhen all checks are clean, report them as a single line in the final report rather than enumerating each one. Only expand a check when it actually flagged something.
This step exists because Semgrep only catches known patterns. These checks catch the class of issues that static analysis misses.
Do not stream intermediate findings to the user.
Accumulate findings during triage, then produce exactly one final report using the format below.
If post mode was requested, write a single review JSON payload and post it via:
bash .agents/scripts/post_github_review.sh <review_json_file>Delete the temporary review JSON file after posting.
Keep the report short and decisive. The classification summary already carries the counts — do not repeat non-actionable findings as prose.
Always include:
Only itemise actionable findings in the Findings section:
dataset_vulnerability, needs_manual_reviewDo not itemise findings classified as by_design_with_documentation —
they are reflected in the classification summary counts and that is sufficient.
If the Findings section has nothing actionable, replace it with a single line that names the non-actionable counts (e.g. "None actionable. 3 by-design findings on pre-existing lines.").
For each actionable finding, include:
reference.md for that bucket; for
dataset_vulnerability, pick the ERROR or WARNING recommendation based on
Semgrep severity)If no findings are plausible dataset vulnerabilities, say so explicitly.
Return one final report in this shape:
## Kedro Datasets Security Scan
> Generated with `kedro-plugins-security-review`.
### Overview
- **Mode:** <full codebase | PR>
- **Target:** <repo root | PR #123>
- **Findings reviewed:** <count>
- **Highest Semgrep severities:** <list or "none">
### Classification summary
- **dataset_vulnerability:** <count>
- **needs_manual_review:** <count>
- **by_design_with_documentation:** <count>
### Findings
<For each actionable finding (dataset_vulnerability, needs_manual_review):>
- `path/to/file.py:L42` — `<classification>` — <rule id> — <reason> — <next step>
<If nothing actionable, replace the list with a single line, e.g.:>
None actionable. <count> by-design findings on pre-existing lines.
### Manual review checks
<If all clean, one line:>
All clean (load_args passthrough, docstring accuracy, risk documentation, security suppression comments).
<Otherwise, only list the checks that flagged something, with reasoning.>
### Conclusion
- <short conclusion, or "No plausible dataset vulnerabilities found.">Write one GitHub review payload:
{
"event": "COMMENT",
"body": "## Kedro Datasets Security Scan\n...(final summary report)...",
"comments": [
{
"path": "file.py",
"line": 42,
"side": "RIGHT",
"body": "**dataset_vulnerability:** <reason>\n\nRule: `<rule id>`\nSeverity: `<severity>`\nNext step: <next step>"
}
]
}Use inline comments only for actionable findings tied to changed PR lines:
dataset_vulnerabilityneeds_manual_reviewDo not post inline comments for by_design_with_documentation. Put the full
summary in body, following the same conciseness rules as chat mode.
© kedro-org, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in .agents/skills/kedro-plugins-security-review of kedro-org/kedro-plugins.
Open the folder on GitHubat commit ff0b268
Kedro Plugins Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kedro Plugins Security Review this skillkedro-org/kedro-plugins | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Semgrep Security Scantrailofbits/skills | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| SkepticRaoFoundation/subtensor | 391 | — | ~660 | Automated safety check: Pass | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 |
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
Jeffallan/claude-skills
Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.
Categories
Run a security scan on the kedro-plugins codebase or a pull request. Kedro Plugins Security Review is an agent skill from kedro-org/kedro-plugins. Run a security scan on the kedro-plugins codebase or a pull request.
Kedro Plugins Security Review fits situations like: the user says things like run security scan on the full codebase; run security scan on this PR.
Run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a claude-code`. Or copy the skill folder (.agents/skills/kedro-plugins-security-review in kedro-org/kedro-plugins) into .claude/skills/kedro-plugins-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a codex`. Or copy the skill folder (.agents/skills/kedro-plugins-security-review in kedro-org/kedro-plugins) into .agents/skills/kedro-plugins-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kedro-plugins-security-review, .gemini/skills/kedro-plugins-security-review, .github/skills/kedro-plugins-security-review and .opencode/skills/kedro-plugins-security-review in your project.
Going by SKILL.md and its folder, Kedro Plugins Security Review needs the command-line tools its instructions call (gh, uv, bash and uvx). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use gh, uv and uvx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kedro Plugins Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kedro Plugins Security Review: Kedro Security Review (kedro-org/kedro, 11k stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Skeptic (RaoFoundation/subtensor, 391 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kedro-org (a GitHub organization) maintains it in kedro-org/kedro-plugins, which has 119 GitHub stars. The repository was last updated on October 8, 2026.
Source: kedro-org/kedro-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.