skill-creator
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill automates directory creation and file generation using standard shell utilities such as
mkdirandsed. These operations are transparently described in the instructions and align with the skill's primary function of scaffolding new projects. - [SAFE]: Installation functionality utilizes symbolic links (
ln -sf) to register new skills within the user's home directory (e.g.,~/.copilot/skills/or~/.claude/skills/). This is the standard method for local skill installation on these platforms and requires the user to participate in the workflow. - [SAFE]: Metadata discovery is performed through benign
gitcommands (git config user.name,git rev-parse) to prepopulate skill templates with the author's information, which is common for developer tooling. - [SAFE]: The provided Python validation and packaging scripts (
quick_validate.py,package_skill.py) follow security best practices, including the use ofyaml.safe_load()to prevent arbitrary code execution during YAML parsing. - [SAFE]: External references point to well-known and trusted official documentation (e.g., Anthropic's official GitHub repositories), and no unauthorized network exfiltration or remote code downloads were identified.
Audit Metadata