html-ppt-zhangzara-daisy-days Eval
==================================
Status: failed
Score: 84/100
Risk: high
Decision: do_not_auto_install
Policy: block
Reason: Audit score: Risky
Install:
npx skills add nexu-io/open-design --skill html-ppt-zhangzara-daisy-days
Required checks:
- PASS Task fit: Task wording matches this skill metadata.
- PASS Install path: Install handoff is available.
- PASS Install command safety: standard package or runtime install path
- WARN Trust score: Good trust signals with a few areas worth checking before rollout.
- FAIL Audit score: Risky
- FAIL Agent safety gate: This skill should not be selected by an agent without explicit human security review.
- PASS License clarity: Apache-2.0
- PASS Permission surface: filesystem or document access
Warnings:
- Trust score: Good trust signals with a few areas worth checking before rollout.
- Audit risk risky exceeds max_risk=medium
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
- SKILL.md frontmatter describes a specific customer-onboarding workshop, but the body is mostly a generic template guide; this scope mismatch can confuse an agent about when and how to invoke the skill.
- The workflow in SKILL.md does not include the clarifying-question and critic-pass steps that appear in the example_prompt metadata, so an agent reading only SKILL.md may skip the essential pre-generation questions and final quality check.
- No explicit setup/prerequisites section is present, such as where example.html lives, what assets are required, and how to preview the result.
- The submitted excerpt does not visibly include the LICENSE file or example.html; the skill should verify these files are actually packaged alongside SKILL.md and template.json.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
Validation plan:
1. Inspect repository, README/SKILL.md, license, and recent commits before production use.
2. Install in an isolated workspace or sandbox with no production secrets available.
3. Run the smallest representative task and record files touched, commands run, network access, and outputs.
4. Compare the selected skill against at least one alternative when the eval status is review or failed.
5. Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Do not use when:
- teams that need a vendor-supported SLA
- production agents without a repository review
- SKILL.md frontmatter describes a specific customer-onboarding workshop, but the body is mostly a generic template guide; this scope mismatch can confuse an agent about when and how to invoke the skill.
- Audit risk risky exceeds max_risk=medium
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
- The workflow in SKILL.md does not include the clarifying-question and critic-pass steps that appear in the example_prompt metadata, so an agent reading only SKILL.md may skip the essential pre-generation questions and final quality check.
- No explicit setup/prerequisites section is present, such as where example.html lives, what assets are required, and how to preview the result.
- The submitted excerpt does not visibly include the LICENSE file or example.html; the skill should verify these files are actually packaged alongside SKILL.md and template.json.
URLs:
- Skill: https://www.openagentskill.com/skills/nexu-io-html-ppt-zhangzara-daisy-days
- Audit: https://www.openagentskill.com/skills/nexu-io-html-ppt-zhangzara-daisy-days/audit
- JSON: https://www.openagentskill.com/api/agent/evals?slug=nexu-io-html-ppt-zhangzara-daisy-days