Skill audit report

guidelines-advisor Audit report.

Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.

REVIEWED · REVIEWNeeds reviewGenerated Aug 24, 2026Heuristic metadata audit
84
Audit
76
Trust
85
Quality
81
Security
100
Maintain
92
Install

OpenAgentSkill Trust Score

76
Strong shortlist

OpenAgentSkill Trust Score

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

GitHub adoption

PASS

94

6.8K GitHub stars

Stars/forks activity

PASS

88

6.8K stars, 585 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

100

Pushed today

License clarity

PASS

86

CC-BY-SA-4.0

README/SKILL.md completeness

PASS

86

Metadata includes enough usage and workflow context

Dependency/runtime risk

PASS

82

database surface

Install availability

PASS

92

npx skills add trailofbits/skills --skill guidelines-advisor

Install command safety

PASS

92

standard package or runtime install path

Permission surface

INFO

74

filesystem or document access, database access

Repository evidence

PASS

86

https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor

Review status

INFO

66

AI review data available

Agent Proven outcomes

INFO

54

No agent outcome data yet

Checks

Install and adoption review

9 Passed · 6 Needs review

Install path

92

PASS

npx skills add trailofbits/skills --skill guidelines-advisor

Repository

88

PASS

https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor

License

86

PASS

CC-BY-SA-4.0

Maintenance

100

PASS

Pushed today

AI review

55

CHECK

The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.

README/SKILL.md completeness

86

PASS

Usable description available

Dependency risk

82

PASS

database surface

Install command safety

92

PASS

standard package or runtime install path

Permission surface

74

CHECK

filesystem or document access, database access

Stars/forks activity

88

PASS

6.8K stars, 585 forks; issue activity unavailable in current metadata

Adoption

88

PASS

6.8K GitHub stars

Warnings

  • The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.
  • Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.
  • The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.
  • Quality score needs review

Method

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Compare nearby options

Related skills to audit next