Security Audit
mattpocock/skills:skills/in-progress/batch-grill-me
github.com/mattpocock/skillsTrust Assessment
mattpocock/skills:skills/in-progress/batch-grill-me received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Excessive Permissions via Autonomous Sub-Agent Tool Execution.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on July 17, 2026 (commit 9603c1cc). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Excessive Permissions via Autonomous Sub-Agent Tool Execution The skill instructs the LLM to autonomously dispatch sub-agents to query the environment (filesystem, tools, etc.) to find facts without user intervention or confirmation ('dispatch a sub-agent to find it — don't ask the user for anything you could look up yourself'). In an agentic environment like claude_code, this can lead to unauthorized filesystem access, execution of arbitrary tools, or data exposure if the agent autonomously explores sensitive directories or runs tools based on untrusted or unverified context. Require explicit user confirmation before dispatching sub-agents or executing tools to inspect the local filesystem and environment. Limit the scope of automated environment discovery. | LLM | SKILL.md:11 |
Scan History
Embed Code
[](https://skillshield.io/report/f7b23ec9c1240df0)
Powered by SkillShield