skill-forge-publish

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation and template provider for developers to share their own skills. It does not contain any executable malicious payloads.
  • [COMMAND_EXECUTION]: The skill includes a template for an install.sh script designed to copy files into the standard Claude Code directories (~/.claude/skills and ~/.claude/agents). The script uses safe practices such as set -euo pipefail and does not require administrative privileges (sudo).
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs users to avoid including secrets or API keys in their distributions and provides a .gitignore template that excludes .env files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 02:59 AM