eval-driven-dev
What this skill does
The skill 'eval-driven-dev' is a development tool for improving AI applications through evaluation-driven development. It focuses on setting up QA, adding tests, and evaluating Python-based LLM applic
github/github - Potential Code Injection - 37k stars
Threat analysis
Skill info
pkg:github/github/awesome-copilot@dae77f2?skill=eval-driven-devAssessments (2)
Potential Code Injection
Potential Code Injection via local-llm-review
resources/setup.sh
The script uses `uv add` and `uv pip install` to install packages, but the command is cut off and incomplete. This could be a red flag if the script is attempting to install untrusted or malicious pacInsecure Package Installation
Insecure Package Installation via local-llm-review
resources/setup.sh
The script attempts to install 'pixie-qa[all]' without explicitly specifying a trusted source or version pinning. This could lead to the installation of potentially insecure or malicious versions of tBadge
Add the Anomity scan badge for eval-driven-dev to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of eval-driven-dev? Report an issue or request a rescan.




