Trust Assessment
critical-path-analyzer received a trust score of 79/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 2 findings: 0 critical, 1 high, 1 medium, and 0 low severity. Key findings include Missing required field: name, Arbitrary File Write via Unvalidated Path.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Arbitrary File Write via Unvalidated Path The `export_analysis` method directly uses the `output_path` argument to create an Excel file without any path validation or sanitization. An attacker could provide a malicious path (e.g., using directory traversal sequences like `../` or absolute paths) to write files to arbitrary locations on the file system. This could lead to overwriting critical system files, denial of service, or data exfiltration if the agent has sufficient write permissions to sensitive directories. Implement robust path validation and sanitization for the `output_path` argument. Ensure the path is confined to an allowed, sandboxed directory and does not contain directory traversal sequences. Additionally, restrict the agent's file system write permissions to only necessary and designated output directories. | LLM | SKILL.md:264 | |
| MEDIUM | Missing required field: name The 'name' field is required for claude_code skills but is missing from frontmatter. Add a 'name' field to the SKILL.md frontmatter. | Static | skills/datadrivenconstruction/critical-path-analyzer/SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/5e0ba87bbbb22ea3)
Powered by SkillShield