skill-creator

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Python subprocess module in several files (scripts/run_eval.py, scripts/improve_description.py, and eval-viewer/generate_review.py) to execute shell commands. These include running the official claude CLI tool to test skill triggering, as well as using lsof and kill to manage the local HTTP server used for the evaluation viewer. These are legitimate uses of command execution required for the skill's meta-development features.\n- [EXTERNAL_DOWNLOADS]: The evaluation viewer template (eval-viewer/viewer.html) references an external JavaScript library, SheetJS, hosted on cdn.sheetjs.com. This library is used to provide spreadsheet rendering capabilities within the skill's reporting interface and is a well-known service in the technology industry.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — skill-creator