laststance-publish-skill
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard shell commands such as
mkdir,cp, andgitto manage skill files and update a repository. - [COMMAND_EXECUTION]: The instructions include the use of
npx skills, which executes theskillsCLI package to manage skill installations and symlinks. - [DATA_EXFILTRATION]: The skill moves files from local agent directories (~/.claude/skills/) to a remote repository. This behavior is consistent with the skill's stated purpose of publishing content to a central repository owned by the author.
Audit Metadata