skill-scout
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is instructed to execute the command
npx @ericrisco/rsc capabilitiesto list installed skills, agent files, and catalog IDs. It also records findings usingnpx @ericrisco/rsc capabilities gap-log. These commands utilize a CLI tool provided by the skill's author, 'ericrisco', representing standard vendor functionality. - [EXTERNAL_DOWNLOADS]: Documentation within
references/install-commands.mddescribes manual installation methods for the user, including the use ofcurl | tarto fetch remote skill archives. These patterns are presented as instructions for human-initiated installation and are not executed autonomously by the agent. - [DATA_EXFILTRATION]: The skill records identified capability gaps into local files such as
skill-gaps.jsonland.rsc/automation-gaps.md. The instructions include a strict "privacy boundary" that mandates the agent use its own observations and paraphrase descriptions rather than including user-supplied text in the logs. - [SAFE]: The provided script
scripts/verify.shperforms local, network-free validation of the generated JSONL log files. It uses a hardcoded whitelist of known catalog IDs to prevent the agent from recommending non-existent skills.
Audit Metadata