create-skill

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a meta-utility for skill development. All identified behaviors (file system operations for skill creation, zip packaging, and documentation generation) are consistent with its stated purpose.
  • [COMMAND_EXECUTION]: The skill documentation and internal scripts reference the execution of local Python and Bash scripts (e.g., init_skill.py, package_skill.py). These are standard development tools provided within the skill's own directory and do not involve untrusted input or remote code execution.
  • [EXTERNAL_DOWNLOADS]: No external network operations or downloads from unverified sources were detected. The SOURCE_URL points to the author's official GitHub repository, which is used for metadata injection during packaging.
  • [DATA_EXFILTRATION]: There are no patterns suggesting the collection or transmission of sensitive user data. The scripts perform local file manipulations (creating directories, writing templates) within the user's specified project path.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-skill