skill-scout

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is instructed to execute the command npx @ericrisco/rsc capabilities to list installed skills, agent files, and catalog IDs. It also records findings using npx @ericrisco/rsc capabilities gap-log. These commands utilize a CLI tool provided by the skill's author, 'ericrisco', representing standard vendor functionality.
  • [EXTERNAL_DOWNLOADS]: Documentation within references/install-commands.md describes manual installation methods for the user, including the use of curl | tar to fetch remote skill archives. These patterns are presented as instructions for human-initiated installation and are not executed autonomously by the agent.
  • [DATA_EXFILTRATION]: The skill records identified capability gaps into local files such as skill-gaps.jsonl and .rsc/automation-gaps.md. The instructions include a strict "privacy boundary" that mandates the agent use its own observations and paraphrase descriptions rather than including user-supplied text in the logs.
  • [SAFE]: The provided script scripts/verify.sh performs local, network-free validation of the generated JSONL log files. It uses a hardcoded whitelist of known catalog IDs to prevent the agent from recommending non-existent skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — skill-scout