Skill Detail

ShellCheck Configuration and Static Analysis

This skill provides documentation about using ShellCheck for static analysis of shell scripts, including how to configure it and apply best practices.

GitHub:sickn33/antigravity-awesome-skills shellcheck-configuration
version 7a975c11c415
static analysis only
no human review yet
Use Caution

Current public label

Use Caution

Because the skill references `sudo`, it is labeled 'use_caution' to highlight the potential for privilege escalation.

This label is currently coming from the automated scorecard.

Automated result

Use Caution

Driftloom found the skill includes documentation and references the `sudo` command, which can change the risk profile.

1 medium, 1 low Final label: use caution.

Human review

No human review has been recorded yet.

The current public label is still relying on automation. A human has not weighed in yet.

What happened

Driftloom completed a static scan. It inspected the skill files, recorded findings, and generated a scorecard.

Runtime evidence

No sandbox runtime result has been recorded yet.

What did not happen

  • Driftloom did not run this skill in an isolated sandbox yet.
  • This label is not a guarantee that the skill is safe, bug-free, or appropriate for every environment.
  • A good score does not replace human judgment when a skill touches secrets, shell access, or external systems.

Source provenance

Source: Workspace import

Originally ingested from a local workspace copy.

Scorecard

Safety
85
Quality
94
Transparency
100
Operational
92
Maintenance
76

1 medium, 1 low Final label: use caution.

Severity mix: 1 medium, 1 low

What Driftloom checked

  • Read the skill files and metadata to understand what the skill claims to do.
  • Looked for shell commands and risky command patterns.
  • Looked for external URLs and network behavior.
  • Looked for secrets and credential handling clues.
  • Checked whether the skill structure and references looked internally consistent.

Findings

Privilege escalation command referenced
shell.sudo · safety
Medium

The source references sudo. That may be legitimate, but it changes the risk profile.

File: SKILL.md
Evidence: sudo
Documentation-only skill structure
structure.docs_only · quality
Low

The source looks almost entirely documentation-based, with no obvious code or config files to inspect. That does not make it bad, but it limits how much automation can meaningfully verify.

File: SKILL.md