Pre-install eval
Soar eval report.
A machine-readable install decision for agents: task fit, Trust Score, Audit Score, install safety, permission surface, and a concrete validation plan before this skill touches a workspace.
do not auto install
Permission surface: shell or command execution, filesystem or document access
Required gates
Checks an agent must pass before install
Task fit
84
Task wording matches this skill metadata.
- Evaluate Soar before installing it in an agent workflow
- data-analysis
- Database and SQL workflows; Claude Code teams; teams that value GitHub adoption signals
Install path
92
Install handoff is available.
- npx skills add XiaoMi/soar
Install command safety
92
standard package or runtime install path
- npx skills add XiaoMi/soar
Trust score
80
Good trust signals with a few areas worth checking before rollout.
- Strong shortlist
- 8.8K GitHub stars
- Apache-2.0
Audit score
74
Needs review
- Permission surface may require sandboxing
Agent safety gate
42
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
- Test manually in an isolated workspace and compare against safer alternatives.
- High-risk permission hints: Shell or command execution
License clarity
86
Apache-2.0
- Apache-2.0
Permission surface
50
shell or command execution, filesystem or document access
- Shell or command execution: high
- Network access: medium
- Filesystem access: medium
Validation plan
What the agent should do next
- 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
- 2Install in an isolated workspace or sandbox with no production secrets available.
- 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
- 4Compare the selected skill against at least one alternative when the eval status is review or failed.
- 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Do not use when
Conditions that require another skill
- teams that require actively maintained dependencies
- production agents without a repository review
- Repository looks stale
- High-risk permission hints: Shell or command execution
- Permission surface may require sandboxing
- Repository appears stale
Supporting checks
Trust signals behind the decision
README/SKILL.md completeness
warn74
Public metadata needs stronger README/SKILL.md context
Recent maintenance
fail22
3y since push
Alternatives available
pass82
Alternative skills are available for comparison.