skill-creator
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runandsubprocess.Popenin several scripts (eval-viewer/generate_review.py,scripts/run_eval.py,scripts/improve_description.py) to manage local development tasks. - Evidence:
subprocess.Popenis used inrun_eval.pyto launchclaude -pfor testing skill triggering. - Evidence:
subprocess.runis used inimprove_description.pyto call the localclaudeCLI for description optimization. - Evidence:
generate_review.pyuseslsofandkillvia subprocess to manage its internal web server ports. - [EXTERNAL_DOWNLOADS]: The
eval-viewercomponent loads theSheetJSlibrary from a well-known content delivery network (cdn.sheetjs.com). - Evidence:
eval-viewer/viewer.htmlincludes a script tag forxlsx.full.min.jsfromcdn.sheetjs.comto render spreadsheets during eval review.
Audit Metadata