skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides utility scripts (scripts/init_skill.py and scripts/package_skill.py) that perform standard filesystem operations such as creating directories, writing boilerplate files, and packaging contents into ZIP archives. These actions are transparent and align with the skill's stated purpose as a development tool.
  • [DYNAMIC_EXECUTION]: The init_skill.py script generates basic Python and Markdown templates from static strings. This template-based generation is a standard initialization pattern and does not execute or evaluate untrusted code.
  • [EXTERNAL_DOWNLOADS]: The validation script (scripts/quick_validate.py) requires the PyYAML package to safely parse metadata. This is a standard, well-known dependency for YAML processing in Python environments.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No network operations, API calls, or attempts to access sensitive system files (e.g., SSH keys, environment variables) were found. File operations are restricted to the user-specified project path.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — skill-creator