anthropic-skilljar-extractor
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute a local Python script
scripts/extract_course.pyto automate the extraction and organization of course materials. - [EXTERNAL_DOWNLOADS]: The extraction script fetches course metadata and HTML from
anthropic.skilljar.comand downloads visual assets from an Amazon CloudFront CDN (d7juhi4i8fsw0.cloudfront.net). These operations are directed at well-known services and are consistent with the skill's stated functionality. - [DATA_EXFILTRATION]: While the script performs network operations, they are limited to fetching data from the target site and downloading images to a local directory. No evidence of unauthorized data transmission or sensitive file access was found.
Audit Metadata