aliyun-skill-creator

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script eval-viewer/generate_review.py uses subprocess calls to execute the lsof utility. This is part of a port management routine to ensure a local HTTP server can be started for reviewing evaluation results without port conflicts.
  • [COMMAND_EXECUTION]: The scripts/run_eval.py script programmatically invokes the claude command-line interface via subprocess to test if specific skill descriptions correctly trigger the agent for given queries.
  • [SAFE]: The skill references well-known services and trusted sources, including Google Fonts for report styling and the Anthropic API for the iterative optimization of skill descriptions. These operations are transparent and consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:49 AM