Trust Assessment
bim-to-schedule-4d received a trust score of 79/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 2 findings: 0 critical, 1 high, 1 medium, and 0 low severity. Key findings include Missing required field: name, Arbitrary File Write via export_links method.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Arbitrary File Write via export_links method The `export_links` method allows writing skill-generated data to an arbitrary file path specified by the `output_path` argument. If this argument is controlled by untrusted input, it could lead to overwriting existing files, creating new files in sensitive locations, or filling up disk space, potentially causing denial of service or data integrity issues. This is an excessive permission vulnerability as the skill can write to any location on the filesystem accessible to the agent. Implement strict validation and sanitization of the `output_path` argument. Restrict file writes to a predefined, secure directory (e.g., a temporary directory or a user-specific output directory). Ensure the path does not contain directory traversal sequences (e.g., `../`) and consider using a file picker or a mechanism that prevents arbitrary path specification by the user. If the skill is meant to be used in a sandboxed environment, ensure the sandbox properly restricts file system access. | LLM | SKILL.md:160 | |
| MEDIUM | Missing required field: name The 'name' field is required for claude_code skills but is missing from frontmatter. Add a 'name' field to the SKILL.md frontmatter. | Static | skills/datadrivenconstruction/bim-to-schedule-4d/SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/a867741d7c1daa30)
Powered by SkillShield