skill-vetter
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches repository statistics and file lists from the official GitHub API and file content from GitHub's raw content domain. These operations are restricted to public metadata and source code for the purpose of manual or automated review.
- [COMMAND_EXECUTION]: Utilizes standard command-line tools like curl and jq to retrieve and process information. The instructions provide specific patterns for checking stars, forks, and update times to verify the reputation of a skill's source.
- [DATA_EXFILTRATION]: Does not perform any exfiltration. Although the skill mentions sensitive file paths such as SSH and AWS credentials, it does so exclusively within a checklist of 'red flags' for the agent to watch for when auditing other skills.
- [PROMPT_INJECTION]: The skill provides a structured vetting protocol that encourages the agent to maintain a high level of scrutiny and follow a defined verification process, which enhances the overall safety of the agent's environment.
Audit Metadata