Oathe Security Badge

Is bjg4/bgskillz safe?

https://github.com/bjg4/bgskillz

95
SAFE

BGSkillz is a comprehensive educational skill for teaching Claude skill development best practices and providing development utilities. All security categories score highly with no significant vulnerabilities detected. The executable scripts are legitimate utilities focused on skill scaffolding and validation.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 95/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 95/100 · 5%

Findings (1)

LOW Executable Python Scripts Present -10

The skill contains three executable Python scripts (init_skill.py, validate_skill.py, package_skill.py) that perform file system operations for skill development tasks.