Pre-install eval
get-env-var Eval report.
A machine-readable install decision for agents: task fit, Trust Score, Audit Score, install safety, permission surface, and a concrete validation plan before this skill touches a workspace.
do not auto install
Agent safety gate: This skill should not be selected by an agent without explicit human security review.
Required gates
Checks an agent must pass before install
Task fit
70
Task fit is weak; compare alternatives before selecting.
- Evaluate get-env-var before installing it in an agent workflow
- security
- Testing and QA workflows; Claude Code teams; teams that value GitHub adoption signals
Install path
92
Install handoff is available.
- npx skills add Devin-AXIS/iPolloWork --skill get-env-var
Install command safety
92
standard package or runtime install path
- npx skills add Devin-AXIS/iPolloWork --skill get-env-var
Trust score
73
Good trust signals with a few areas worth checking before rollout.
- Strong shortlist
- 4.6K GitHub stars
- NOASSERTION
Audit score
81
Needs review
- Dependency or permission surface needs review
Agent safety gate
37
This skill should not be selected by an agent without explicit human security review.
- Do not auto-install. Inspect the source, dependencies, and permission surface first.
- Metadata combines secrets access with shell or command execution
License clarity
86
NOASSERTION
- NOASSERTION
Permission surface
22
secrets or environment access, shell or command execution
- Shell or command execution: high
- Browser automation: medium
- Network access: medium
Validation plan
What the agent should do next
- 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
- 2Install in an isolated workspace or sandbox with no production secrets available.
- 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
- 4Compare the selected skill against at least one alternative when the eval status is review or failed.
- 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Do not use when
Conditions that require another skill
- teams that need a vendor-supported SLA
- production agents without a repository review
- Repository license is NOASSERTION, which means no clear license is specified. This may create ambiguity about usage rights.
- No OpenAgentSkill engagement data yet
- High-risk permission hints: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Supporting checks
Trust signals behind the decision
README/SKILL.md completeness
pass86
Metadata includes enough usage and workflow context
Recent maintenance
pass100
1d since push
Alternatives available
pass82
Alternative skills are available for comparison.