Skip to content
TrustedSkillsbeta
Back to all skills

Last30Days

Listed
mvanhorn·vlatest·other

Last30Days — provides AI agent assistance for software development workflows.

Install on your platform

Showing Claude Code. One command installs this skill into any of the agents below.

  1. 1

    Run this in your project

    terminal
    $ npx skills add mvanhorn/last30days-skill --skill last30days -a claude-code
  2. Uses the open-source skills CLI and needs Node.js. Add -g to install it for your user instead of this project.

What we know about this skill

Publisher

mvanhorn

Taken from the source listing. We haven't verified who controls this account.

Install target

Live repository

Not pinned. Installing fetches whatever the repository holds at the time you run the command.

No human has reviewed this code. The checks below are a static scan of the files at one commit — nobody has run this skill or judged whether it works. A skill runs with whatever access you give your agent, so read the source before you install it.

Automated safety checks

scanned

This skill failed 3 of 6 checks. A failure is not proof of bad intent; it means something in the code needs a human to look at it before you run it.

  • No undeclared network calls: failed

    Contacts 37 hosts that are neither well-known infrastructure nor declared in the skill's frontmatter: api.ashbyhq.com, api.bsky.app, api.exa.ai, api.ht-ml.app, api.lever.co….

    Every host the skill dials — from its scripts, its config endpoints or the commands it tells the agent to run — is either well-known package and API infrastructure or declared in its own frontmatter. Links in documentation are not counted.

    Hosts contacted

    x.comundeclared127.0.0.1localgenerativelanguage.googleapis.commodel providert.meundeclaredwww.amazon.comundeclaredx.aiundeclaredbsky.socialundeclaredapi.bsky.appundeclaredbsky.appundeclareddi.ggundeclaredhost.docker.internallocalwww.reddit.comundeclaredhn.algolia.comundeclaredgamma-api.polymarket.comundeclaredapi.github.comsource hostdripstack.xyzundeclaredwww.w3.orgstandardsgithub.comsource hostapi.search.brave.comundeclaredapi.exa.aiundeclaredgoogle.serper.devundeclaredapi.parallel.aiundeclarednews.ycombinator.comundeclarednodejs.orgdocumentationffmpeg.orgundeclaredapi.ht-ml.appundeclaredscrapecreators.comundeclaredapi.scrapecreators.comundeclaredwww.instagram.comundeclaredboards-api.greenhouse.ioundeclaredapi.ashbyhq.comundeclaredapi.lever.coundeclaredapply.workable.comundeclaredapi.smartrecruiters.comundeclaredjobs.smartrecruiters.comundeclaredwww.facebook.comundeclaredsearch.parallel.aiundeclaredopenrouter.aimodel providerapi.perplexity.aiundeclaredwww.pinterest.comundeclaredreddit.comundeclaredarxiv.orgundeclaredwww.techmeme.comundeclaredwww.trustpilot.comundeclaredboards.greenhouse.ioundeclared

    What it found (3 of 72)

    • skills/last30days/scripts/box_chrome_login.py:47contacts x.com
      LOGIN_URL = "https://x.com/login"
    • skills/last30days/scripts/lib/bird_x.py:698contacts x.com
      url = f"https://x.com/{screen_name}/status/{tweet['id']}"
    • skills/last30days/scripts/lib/grok_x.py:721contacts x.com
      "url": f"https://x.com/{handle}/status/{post_id}",
  • No credential access: failed

    Touches credential material in 22 places.

    Neither the code nor the SKILL.md instructions read SSH keys, cloud credentials, keychains, token stores, browser cookie databases or dotfiles that hold secrets.

    What it found (3 of 22)

    • skills/last30days/SKILL.md:303environment file outside the project
      grep -q "SETUP_COMPLETE=true" ~/.config/last30days/.env 2>/dev/null && echo "1" || echo "FIRST_RUN_DETECTED"
    • skills/last30days/scripts/last30days.py:4218environment file outside the project
      # ~/.config/last30days/.env, which env.py loads but does not propagate
    • skills/last30days/scripts/lib/backends.py:202environment file outside the project
      prescription = note or f"set {key_var} in ~/.config/last30days/.env"
  • No pipe-to-shell installers: failed

    Runs code fetched at install time in 5 places.

    No `curl … | sh` pattern, in the code or in the instructions, that runs code fetched at run time.

    What it found (3 of 5)

    • skills/last30days/scripts/lib/backends.py:303remote script piped into a shell
      "install the Grok CLI: curl -fsSL https://x.ai/cli/install.sh | bash, "
    • skills/last30days/scripts/lib/grok_x.py:8remote script piped into a shell
      Install: curl -fsSL https://x.ai/cli/install.sh | bash   (or npm i -g @xai-official/grok)
    • skills/last30days/scripts/lib/health.py:197remote script piped into a shell
      "install the Grok CLI: curl -fsSL https://x.ai/cli/install.sh | bash, then run `grok login`",
  • Declares what it does: passed

    SKILL.md parses and declares a name and a description.

    SKILL.md exists, its frontmatter parses, and it declares a name and a description.

  • No obfuscated payloads: passed

    No encoded or obfuscated payloads.

    No base64, hex or compressed blob is decoded and then executed, and no encoded shell commands.

  • Pinned to a commit: passed

    Scanned mvanhorn/last30days-skill at 084662b501.

    The exact upstream commit SHA that was scanned is recorded, so the result refers to specific bytes.

Scanned
60 files, 40,752 lines
This is a static scan, not a review. It reads the skill's files; it does not run them, and it cannot tell you whether the skill is any good or whether the code does what its description says. A skill runs with whatever access you give your agent.
What each check looks for →

About this skill

Last30Days — provides AI agent assistance for software development workflows.