Phy Skill Creator

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The SKILL.md generally matches a 'skill-creator' purpose, but it repeatedly assumes local helper scripts and agent/subagent capabilities (e.g., eval-viewer/generate_review.py, 'claude-with-access-to-the-skill', background runs) that are not included or declared — this mismatch could surprise users or cause the agent to attempt actions your environment doesn't provide.

This SKILL.md reads like a useful playbook for designing and evaluating skills, but it repeatedly assumes helper scripts and agent-execution capabilities that are not included in the package. Before installing or enabling this skill, ask the provider (or the skill author) to: 1) list any required external tools/scripts (e.g., eval-viewer/generate_review.py) and either bundle them or confirm they exist in your environment; 2) describe what agent/subagent or background-run capabilities it will invoke and whether those runs will send data off your machine or require credentials; and 3) provide a minimal example run so you can test in a sandbox. If you cannot verify those external dependencies, avoid giving the skill broad autonomous access or running it against sensitive data until you can confirm the environment and scripts the skill expects are present and trusted.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.