skill-creator-advanced
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security threats were identified during the analysis of the 118 files provided.
- [COMMAND_EXECUTION]: The skill uses
subprocess.runin helper scripts (infer_destination.py,test_skill.py) for legitimate purposes such as Git repository discovery (git rev-parse) and running its own isolated regression tests. These calls are implemented using argument lists rather than shell strings, minimizing injection risk. - [DYNAMIC_EXECUTION]: The scaffolding utility (
scripts/scaffold.sh) usesctypesto interface with system-level C libraries (libc on Unix-like systems and kernel32 on Windows). This is used to implement platform-specific atomic directory renames (renameat2,renameatx_np, andMoveFileExW) to ensure package integrity during publication. This aligns with the skill's stated purpose of providing production-grade tooling. - [CREDENTIALS_SAFE]: The skill's instructions, templates, and evaluation fixtures consistently demonstrate best practices for secret management, specifically recommending the use of environment variables (e.g.,
$ORBIT_TOKEN,$GITHUB_TOKEN) and secret references rather than hardcoded credentials. - [OBFUSCATION]: No obfuscation, hidden logic, or malicious encoding was detected. The scripts use standard readable Python and Bash logic.
- [REMOTE_CODE_EXECUTION]: No instances of downloading and executing code from remote or untrusted sources were found. External dependencies like PyYAML are treated as optional local requirements.
Audit Metadata