metric-pack-designer

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • Local Script Generation and Execution: The skill guides the user in creating local scripts to generate metric data, which are then processed by the plugin-eval tool. This pattern is a common and legitimate way to extend evaluation rubrics locally.
  • Command Execution: The workflow involves running the plugin-eval command to analyze paths using custom manifests. This is an intended functionality for developers to test their rubrics.
  • Data Ingestion and Processing Surface: The created rubrics process data from user-specified paths.
  • Ingestion points: The <path> argument for the plugin-eval command in SKILL.md.
  • Boundary markers: No explicit delimiters or warnings for embedded instructions are specified in the workflow.
  • Capability inventory: Includes the plugin-eval command and the ability to create local manifest and script files (SKILL.md).
  • Sanitization: Not explicitly defined, as the skill focus is on rubric design for local use.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 09:39 AM
Security Audit — agent-trust-hub — metric-pack-designer