eval-skills

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local run.sh scripts using subprocess.run with list-based arguments in eval_runner.py. This is the intended behavior for running behavioral tests and uses secure implementation patterns.
  • [EXTERNAL_DOWNLOADS]: The run.sh script leverages uv, a trusted dependency manager, to execute the Python environment.
  • [DATA_EXFILTRATION]: Sourcing of a .env file from the project root in run.sh is performed to provide necessary configuration for tests, which is standard in development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — eval-skills