Make SkillSAFE
EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.
Overview
EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.
1aecdbaaf9a2OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| codex | mentioned | |
| copilot | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: make-skill description: 'Create and evaluate new Agent Skills for GitHub Copilot. Use when asked to create, scaffold, or add a skill. Generates SKILL.md, optional resources, and a paired Vally harness eval.' --- # Create Skill This skill helps you scaffold new agent skills that conform to the Agent Skills specification. Agent Skills are a lightweight, open format for extending AI agent capabilities with specialized knowledge and workflows. ## When Not to Use - Creating custom agents (use the agents/ directory pattern) - Adding language-specific, framework-specific, or module-specific coding guidelines (use file-based instructions instead) ### Key Principles - **Frontmatter is critical**: `name` and `description` determine when the skill triggers—be clear and comprehensive - **Concise is key**: Only include what agents don't already know; context window is shared - **Useful instructions**: Only include information that's stable, not easily searchable and can be used for any task within the skill's scope - **No duplication**: Information lives in SKILL.md OR reference files, not both ## Workflow ### Step 1: Investigate the Topic Build deep understanding of the relevant topics using the repository content, existing documentation, and any linked external resources. After investigating, verify: - [ ] Can explain what the skill does in one paragraph - [ ] Can list 3-5 specific scenarios where the skill is applicable - [ ] Can identify common pitfalls or misconceptions about the topic - [ ] Can outline a step-by-step skill workflow with clear validation steps - [ ] Have search queries for deeper topics - [ ] Can determine if the skill should be user-invocable or background knowledge only If there are any ambiguities, gaps in understanding, or multiple valid approaches, ask the user for clarification before proceeding to skill creation. Also, evaluate whether the task might be better handled by a custom agent, agentic workflow, an existing skill or multiple narrower skills, and discuss this with the user if relevant. ### Step 2: Create the skill directory ``` .agents/skills/<skill-name>/ ├── SKILL.md # Required: instructions + metadata ``` ### Step 3: Generate SKILL.md with frontmatter Create the file with required YAML frontmatter: ```yaml --- name: <skill-name> description: <description of what the skill does and when to use it> user-invocable: <Optional, defaults to true. Set to false for background knowledge skills.> argument-hint: <Optional, guidance for how agents should format arguments when invoking the skill.> disable-model-invocation: <Optional, set to true to prevent agents from invoking the skill and only allow to be used through manual invocation.> compatibility: <Optional, specify any environment, tool, or context requirements for the skill.> metadata: <Optional, key-value mapping for additional metadata that may be relevant for discovery or execution.> allowed-tools: <Optional, list of pre-approved tools that agents could use when invoking the skill.> --- ``` ### Step 4: Add body content sections Include these recommended sections, following this file's structure: 1. **<Human-readable skill name>**: One paragraph describing the outcome beyond what's already in the description 2. **When Not to Use**: Bullet list of exclusions, optional 3. **Inputs and Outputs**: Example inputs and expected outputs, if applicable 4. **Workflow**: Numbered steps with checkpoints 5. **Testing**: Instructions for how to create automated tests for the skill output, if applicable 6. **Validation**: How to confirm the skill worked correctly 7. **Common Pitfalls**: Known traps and how to avoid them, optional ### Step 5: Add and populate optional directories if needed ``` .agents/skills/<skill-name>/ ├── SKILL.md ├── scripts/ # Optional: executable code that agents can run ├── references/ # Optional: REFERENCE.md (Detailed technical reference), FORMS.md (Form templates or structured data formats), domain-specific instruction files └── assets/ # Optional: templates, resources and other data files that aren't executable or Markdown ``` ### Step 6: Write Scripts (Script-driven Only) - Prefer PowerShell, but can also use Python or JavaScript - Standard param block with defaults - Ensure scripts produce clear, structured, and parseable console output (for example, section headers and status lines) - Emoji status: ✅ green / ⚠️ yellow / 🔴 red - **Fail-closed error handling** — Unknown ≠ Healthy > ❌ **NEVER** count API failures as success. Return "Unknown" and exclude from positive counts. ### Step 7: Author and validate the harness evaluation Create `eng/harness-evaluation/skills/<skill-name>/eval.yaml` and follow the authoring and validation rules in `eng/harness-evaluation/README.md`. Do not add a `skill-invocation` grader; the runner separately requires exact invocation of `<skill-name>` in every treatment trial so control and treatment share the same quality score. The eval must meaningfully distinguish the skilled treatment from the unskilled control. Also verify: - [ ] The skill name does not start or end with a hyphen, contain consecutive hyphens, or exceed 64 characters - [ ] YAML frontmatter name matches the directory name exactly and all frontmatter fields are valid - [ ] SKILL.md is under 500 lines and 5000 tokens, splitting stable detail into references when needed - [ ] File references are relative and instructions are actionable and specific - [ ] Instructions do not duplicate `.github/copilot-instructions.md` or `.github/instructions/` - [ ] The workflow has numbered steps and observable success criteria - [ ] No secrets, tokens, or internal URLs are included - [ ] Optional directories are used appropriately - [ ] Scripts handle edge cases, fail closed, and return structured, helpful errors - [ ] The paired Vally comparison demonstrates distinctive value over the unskilled control ### Step 8: Test with Multi-Model Subagents Fo
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
1aecdbaaf9a2full audit observations/trust-audit/skill/dotnet__make-skill.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1aecdbaaf9a2 | SAFE | B | 89 | first audit |
Questions
What does the Make Skill skill do?
EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.
Is Make Skill safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Make Skill access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Make Skill work with?
Its documentation mentions codex and copilot. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (1aecdbaaf9a2), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.