skill-vetter
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes shell command templates that use
curlto fetch repository metadata and file contents from GitHub (api.github.comandraw.githubusercontent.com). These references target a well-known service for the purpose of static inspection and metadata retrieval. - [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The skill's primary function is to define a protocol for detecting data exfiltration and credential theft in other skills.
- [PROMPT_INJECTION]: The instructions are clear, meta-instructional guidelines for a security task and do not attempt to override the host agent's safety protocols or core instructions.
- [COMMAND_EXECUTION]: The skill provides utility commands for the agent to use
curlandjqfor auditing. These are limited to read-only operations against trusted GitHub APIs. - [SAFE]: The skill is a security tool designed to mitigate risks by providing a structured vetting protocol. It does not contain executable scripts, hidden code, or dangerous dependencies.
Audit Metadata