kettle-skill-creator

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local helper scripts (promote-skill.py, init-plugin.py, validate-plugin.py) and use the just task runner for repository workflows like just sync and just git::version. These commands are standard for repository maintenance and do not involve untrusted input or shell injection risks.
  • [SAFE]: No malicious behavior, data exfiltration, or obfuscation was detected. The skill's operations are restricted to the local file system (specifically the user's home skill directory and the working repository) and follow best practices for skill management and validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 06:52 PM
Security Audit — agent-trust-hub — kettle-skill-creator