!
Third-party audit

Gen Agent Trust Hub

eval-driven-dev · github/awesome-copilot

Review
Provider summary

The skill establishes a QA and evaluation pipeline by installing the third-party 'pixie-qa' package and executing shell scripts to manage the environment. It captures application data (including inputs, outputs, and internal states) and runs a background web server to display results. Security risks include the automated installation of external dependencies from non-trusted repositories and the runtime execution of local project code within a test harness.

The provider classified the analyzed snapshot as MEDIUM risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
warn
Risk level
MEDIUM
Audited
Apr 28, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.