langsmith-trace
Audited by ZeroLeaks on Apr 15, 2026
The skill's SKILL.md is mostly readable, but carries one notable transparency concern: it references remote script execution without a clear review boundary, which weakens the ability to fully audit what the agent will actually run. Instruction/data separation looks reasonable and the skill does not strongly push the agent to treat external content as trusted policy. However, because behavior analysis was not run and the remote execution path introduces uncertainty about downstream effects, this lands at AT_RISK with medium confidence—the scan passed on prompt injection, but finite testing and the unreviewed remote execution make it impossible to confirm the skill doesn't materially change behavior in all cases.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around remote script execution without review boundary.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Remote script execution without review boundary