skill-creator
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
subprocessmodule inscripts/run_eval.pyandscripts/run_loop.pyto execute theclaudeCLI. This is a core feature used to measure skill triggering and performance in an automated fashion. - [EXTERNAL_DOWNLOADS]: The
eval-viewer/viewer.htmlfile includes a reference to the SheetJS library from a well-known CDN (cdn.sheetjs.com) to enable Excel file rendering within the local results viewer. This is a common and safe implementation for data visualization. - [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of test cases and other agent skills using subagents. This behavior is confined to the user's execution environment and is the intended mechanism for validating skill logic during development.
- [SAFE]: No obfuscation, hardcoded credentials, or unauthorized data exfiltration patterns were found. The local web server used by the results viewer is correctly bound to the loopback interface (
127.0.0.1), ensuring data privacy.
Audit Metadata