Atlas / Skills / alibaba / skill-up

skill-upCAUTION

skills/alibaba/skill-up

An evaluation and evolution tool for Agent Skills.

Verdict
CAUTION
Grade
F
Trust score
58 /100
Version
1.0.0
Hosts
3 documented
License
Apache-2.0
Stars
1,055
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

skill-up

Evaluate Agent Skills, agents, and workspaces. Evolve Skills with evidence.

English | 中文

📖 User Manual · 用户手册

Overview

skill-up is a CLI for evaluating Agent Skills, agents, and their workspaces. It runs declarative cases against an Agent Engine, grades the response and workspace changes, and

Read from source at commit 13ba68522229OBSERVED · 2026-09-24
02

Install

Commands as the repository documents them. They are shown, not run.

npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a codex -y
npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a claude-code -y
npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a codex -y
npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a claude-code -y
npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a codex -y
npx skills add https://github.com/alibaba/skill-up/tree/main/skills/skill-upper -g -a claude-code -y
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
cursormentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: code-stats
description: Analyzes code files and reports statistics including line counts, file counts by extension, and total size. Use this skill whenever the user wants to understand the composition of a codebase - asking about "how many lines of code", "what file types exist", "code distribution", or needing a quick audit of project size and structure. Make sure to invoke this skill when users mention analyzing codebases, counting lines, checking file distributions, or auditing code.
version: 1.0.0
---

# Code Stats Skill

Analyzes code files and generates statistics about a codebase.

## Usage

When invoked, this skill will:
1. Scan the specified directory (defaults to current directory)
2. Count total lines, files by extension
3. Report the largest files
4. Output results in a structured format
5. Sort extension summaries by total line count in descending order

## Output Format

Always use this exact format for the output:

```
# Code Statistics

## Summary
- Total Files: <count>
- Total Lines: <count>
- Total Size: <size_bytes> bytes

## Files by Extension
| Extension | Files | Lines |
|-----------|-------|-------|
| .go | 12 | 1500 |
| .md | 5 | 200 |

## Top 5 File Extensions by Line Count
1. .go — 1500 lines
2. .md — 200 lines

## Largest Files (top 5)
1. main.go (500 lines)
2. util.go (300 lines)
```

If a file has no extension, group it under `(no ext)` in both extension sections.

## Process

1. Use `Bash` with `find` to locate all code files
2. Use `Bash` with `wc -l` to count lines per file
3. Group files with no extension under `(no ext)`
4. Sort both extension summaries by total line count in descending order
5. Aggregate the results into the output format above
6. If no directory is specified, analyze the current working directory

## Examples

- "Analyze the current directory"
- "Run code-stats on ./src"
- "Show me file type distribution"
- "How many lines of Python do we have?"
05

Trust audit

CAUTIONgrade F · trust 58/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
internal/config/customengine_test.go:732
Args:    []string{"--token", "sk-ant-api03-AAAAAAAAAAAAAAAAAAAA"},
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/agent/agent_test.go:895
APIKey:   "dashscope-test-token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/agent/agent_test.go:991
APIKey:   "sk-ant-should-not-appear",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/agent/custom_artifact_url_test.go:211
const secret = "sk-super-secret-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/agent/custom_artifact_url_test.go:239
const secret = "env-super-secret-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/agent/custom_test.go:1024
a := &CustomAgent{BaseAgent: BaseAgent{Cfg: Config{Name: "x", APIKey: "sk-real-secret-token"}}} //nolint:gosec // fake credential fixture
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
skills/skill-upper/SKILL.md:126
curl -fsSL https://raw.githubusercontent.com/alibaba/skill-up/main/install.sh | bash
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/agent/agent_test.go:674
func (r *probeMergeTestRuntime) Exec(_ context.Context, cmd string, _ ExecOptions) (ExecResult, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/agent/claude_code_test.go:939
func (r *claudeCodeTestRuntime) Exec(_ context.Context, command string, opts runtime.ExecOptions) (runtime.ExecResult, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/agent/codex_test.go:1354
func (r *codexTestRuntime) Exec(_ context.Context, command string, opts runtime.ExecOptions) (runtime.ExecResult, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/agent/custom_http_test.go:497
func (f fakeFindRuntime) Exec(_ context.Context, _ string, _ ExecOptions) (ExecResult, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/agent/node_install_test.go:136
func (r *nodeBootstrapTestRuntime) Exec(_ context.Context, command string, _ runtime.ExecOptions) (runtime.ExecResult, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/agent/custom_test.go:478
OutputFile: "../../etc/important",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/agent/custom_test.go:495
Kwargs:    map[string]string{"target": "../../etc/important"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/cli/validate_test.go:12
const testEvalPath = "../../examples/code-stats/evals/eval.yaml"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/evaluator/evaluator_test.go:3805
{name: "nested parent traversal", path: "fixtures/../../secret.txt"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/judge/expect_test.go:313
{Path: "../../etc/passwd", Content: "root"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/model-e2e.yml:214
if curl -fsS http://127.0.0.1:8080/health 2>/dev/null | grep -q healthy; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/design/custom-engine.md:736
{ "name": "remote-report.html", "url": "http://127.0.0.1:8080/artifacts/report.html", "content_type": "text/html" },
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/agent/custom_http_test.go:339
custom := httpEngine("http://127.0.0.1:0")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/agent/custom_http_test.go:455
custom := httpEngine("http://127.0.0.1:0")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
internal/agent/custom_http_test.go:538
custom := httpEngine("http://127.0.0.1:0")

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha 13ba68522229full audit observations/trust-audit/skill/alibaba__skill-up.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-2413ba68522229CAUTIONF58first audit
07

Questions

What does the skill-up skill do?

An evaluation and evolution tool for Agent Skills.

Is skill-up safe to install?

With care. The audit graded it F (58/100) and found 25 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can skill-up access on my machine?

The audit observed that it reaches the network and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does skill-up work with?

Its documentation mentions claude-code, codex and cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (13ba68522229), read on 2026-09-24. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement