skill-smith

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [SAFE]: The skill implements a secure persistence mechanism by drafting new capabilities in a quarantine directory (~/Desktop/seven-skills/.forge/) and enforcing a mandatory security audit before installation. This gates the creation of new skills behind a verification layer.
  • [COMMAND_EXECUTION]: The skill invokes a local Python script (~/Desktop/seven-skills/bouncer/scripts/audit.py) to perform security validation. This is a documented, internal capability used for verifying the integrity and safety of generated content.
  • [REMOTE_CODE_EXECUTION]: The 'Dry-run test' involves executing the steps of a drafted skill to verify functionality. While this involves dynamic execution of generated instructions, the risk is mitigated by the quarantine environment and the requirement for successful auditing and user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 04:01 PM
Security Audit — agent-trust-hub — skill-smith