Evaluation report
Warningsagentlas-security-scan · skill91c0413· 3 months ago
Every check MetaHub ran on this artifact, grouped by area. Static checks run on the source at publish time; behavioral checks run the artifact in a sandbox and judge what it actually does.
Structural
5 passedRepository is reachable
https://github.com/agentlas-ai/Agentlas-OS @ 91c0413 — ★ 128 · Python · Apache-2.0 · last push today
Manifest detected
kind=skill slug=agentlas-security-scan · path=skills/agentlas-security-scan · source=SKILL.md
Slug is URL-safe
"agentlas-security-scan" matches /^[a-z0-9][a-z0-9-]{0,62}$/
Slug is unique within kind
No collision found for skill/agentlas-security-scan
Version is semver
0.1.0
Documentation
5 passedDescription quality
33 words · 208 chars — "Use when an agent folder must pass the Agentlas Cloud 2-stage security scan (sta…"
README is present and substantial
34,217 chars · 16 sections · 12 code blocks
Tags / topics declared
19 total — a2a, agent, agent-framework, agent-os-desktop, agent-skills, agentic-ai (+13)
README has usage / example sections
no labeled section but 12 code blocks document usage
Homepage / docs URL declared
https://agentlas.cloud
Safety
2 passedLICENSE file at repo root
LICENSE
No sensitive files in the repo
scanned for .env, credentials.json, *.pem, .ssh/, AWS / GCP configs — none found
Kind-specific
3 passed1 warningSkill: triggers declaredwarn
No `trigger` phrases in SKILL.md frontmatter
Add `trigger:` lines so Claude knows when to activate this skill — e.g. `when building MCP servers` or `for diagram creation`.
Skill: SKILL.md present
found at skills/agentlas-security-scan/SKILL.md · frontmatter source: SKILL.md
Skill: body content present
396 words · 3,022 chars · 4 sections · 1 code block
Skill: allowed-tools scope
no allowed-tools restriction (Claude may use anything)
Maintenance
3 passedRecent activity
last push today
Tests detected
1 test directory · 37 test files
CI configuration detected
GitHub Actions (1 workflows)
Behavioral
Behavioral results aren't published for this artifact. The publisher sees the full report on their own dashboard.