skills/miles990/evolve-plugin/evolve/Gen Agent Trust Hub

evolve

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs automated version checks by fetching version metadata from the author's public GitHub repository and suggests installing additional modular components from established vendor repositories (e.g., miles990/claude-software-skills).
  • [REMOTE_CODE_EXECUTION]: While the skill facilitates the installation of external plugins, it explicitly instructs the agent to prompt the user for manual confirmation and terminal execution, avoiding silent or hidden background updates.
  • [COMMAND_EXECUTION]: The skill includes utility scripts for project maintenance, such as validating skill manifests and generating plugin metadata, which operate on the local file system using standard bash commands.
  • [DATA_EXFILTRATION]: The skill implements a 'Scope Detection' logic designed to identify sensitive information like API keys and tokens, ensuring they are restricted to local project memory and redacted before being used in global contexts.
  • [SAFE]: The overall architecture emphasizes security guardrails, including the specific denial of elevated privileges (sudo) and the enforcement of isolated environments for high-risk or experimental development tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:30 AM
Security Audit — agent-trust-hub — evolve