Skills fit-scorer
πŸ“¦

fit-scorer

v17.0.0 Content revision r1 Safe πŸ“ Filesystem accessβš™οΈ External commands🌐 Network accessπŸ”‘ Env variables

Rank Influencers for Campaign Fit

Creator shortlists are difficult to compare consistently across audience, credibility, engagement, and campaign needs. This skill applies typed ACE scoring and separates commercial fit.

Supports: Claude Codex Code(CC)
πŸ₯‰ 77 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "fit-scorer" from https://skillstore.io/skills/aaron-he-zhu-fit-scorer.md and its manifest at https://skillstore.io/api/skills/aaron-he-zhu-fit-scorer/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "fit-scorer". Compare three sustainable fashion creators for a conversion campaign.

Expected outcome:

  • Creator A leads commercial fit because audience overlap and availability are strongest.
  • Creator B has an ACE veto from verified inauthentic engagement.
  • Creator C remains provisional because audience authenticity is Unknown.

Using "fit-scorer". Score one YouTube creator with incomplete audience data.

Expected outcome:

  • ACE coverage is incomplete, so no final total is issued.
  • Available engagement evidence is dated and labeled Measured.
  • The report requests audience authenticity data before outreach.

Security Audit

Safe
v7 β€’ 7/12/2026 Open versioned report

Most findings are scanner false positives caused by Markdown code fences, inline code, and relative documentation links. The skill explicitly runs local Python tooling, uses shell command substitution, and expects a YouTube API key. No prompt injection or data-exfiltration intent was found in the reviewed files.

2
Files scanned
507
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (4)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Generic API/secret keys
**Measured YouTube inputs (free key)**: for YouTube candidates, `python3 "${CLAUDE_PLUGIN_ROOT}/scri
The workflow expects YOUTUBE_API_KEY and invokes a connector that can consume this secret-bearing environment value. The use appears legitimate, but the connector process receives credential access.
Medium
Ruby/shell backtick execution
**Measured YouTube inputs (free key)**: for YouTube candidates, `python3 "${CLAUDE_PLUGIN_ROOT}/scri
The skill explicitly instructs the agent to run a local Python YouTube connector. The executable and script path are fixed, but this remains external command execution with a creator handle argument.
Medium
Ruby/shell backtick execution
5. **Run the deterministic scorer.** Follow [`runtime-invocation.md`](../../../references/runtime-in
The inline shell example runs git to resolve a root and then executes rubric-score.py. This is explicit external command execution, not only Markdown formatting.
Medium
Shell command substitution
5. **Run the deterministic scorer.** Follow [`runtime-invocation.md`](../../../references/runtime-in
The root-resolution expression contains $(git rev-parse ...), which executes git in a shell. It is a fixed command, but its result controls the later script path.
Audited by: codex View Audit History β†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/aaron-he-zhu-fit-scorer/audits/7?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/aaron-he-zhu-fit-scorer/security.svg)](https://skillstore.io/skills/aaron-he-zhu-fit-scorer?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/aaron-he-zhu-fit-scorer?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/aaron-he-zhu-fit-scorer/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/aaron-he-zhu-fit-scorer.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA Β· BibTeX Β· CFF)

APA citation

aaron-he-zhu. (2026). fit-scorer security audit report (audit version 7) [Author version 17.0.0]. Skillstore. https://skillstore.io/skills/aaron-he-zhu-fit-scorer/audits/7

BibTeX citation

@techreport{aaron-he-zhu-aaron-he-zhu-fit-scorer-2026, author = {aaron-he-zhu}, title = {fit-scorer security audit report (audit version 7)}, institution = {Skillstore}, year = {2026}, number = {7}, url = {https://skillstore.io/skills/aaron-he-zhu-fit-scorer/audits/7}, note = {Author version 17.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "fit-scorer security audit report (audit version 7)" version: "17.0.0" type: report authors: - name: "aaron-he-zhu" date-released: "2026-07-12" url: "https://skillstore.io/skills/aaron-he-zhu-fit-scorer/audits/7" identifiers: - type: other value: "skillstore:aaron-he-zhu-fit-scorer:audit:7" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
41
Architecture
100
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Prioritize a Campaign Shortlist

Compare shortlisted creators under one campaign goal and identify evidence-backed outreach priorities.

Standardize Client Recommendations

Apply one typed rubric across creators while keeping client-specific commercial fit separate.

Audit Creator Evidence

Review credibility vetoes, missing metrics, and confidence before approving a partnership.

Try These Prompts

Score One Creator
Score @[handle] for [campaign]. Use goal [goal] and list the evidence needed before making a recommendation.
Compare a Shortlist
Compare @[handle1], @[handle2], and @[handle3] for [campaign]. Show ACE results separately from commercial fit.
Assess Evidence Gaps
Audit these creator metrics for [campaign]. Mark missing data Unknown, identify critical controls, and explain what prevents a final score.
Build an Advanced Ranking
Rank [creators] for [campaign] using [goal]. Include typed context, dated evidence, veto checks, commercial terms, confidence, and rerun conditions.

Best Practices

  • Use the same evidence window, cohort, and campaign goal for every compared creator.
  • Keep ACE results separate from campaign-specific commercial-fit scores.
  • Verify critical failures and refresh stale metrics before approving outreach.

Avoid

  • Do not treat missing or refused private data as a failure.
  • Do not hand-calculate an ACE total when the deterministic scorer is unavailable.
  • Do not let commercial fit override an ACE veto or unresolved evidence gap.

Frequently Asked Questions

Does this skill find influencers?
No. It scores a supplied shortlist. Use an influencer discovery workflow to source additional candidates.
What is the ACE rubric?
ACE evaluates creator Audience, Credibility, and Engagement through 12 typed items and defined critical controls.
Can it score creators without integrations?
Yes. Users can provide the required metrics, but missing evidence remains Unknown and may prevent a final total.
Does brand fit change the ACE score?
No. Brand and campaign fit belong in a separate commercial matrix and never enter the ACE result.
Can it compare creators across platforms?
Yes, when each creator has clear platform, tier, niche, cohort, and evidence context.
Does it save reports automatically?
No. It should persist reports only after explicit user authorization.

Developer Details

License

Apache-2.0

Author version

v17.0.0

Skillstore revision

r1

Ref

d71c7417a35d5c2624161bd2fe8de8a41a362128

Maintenance freshness

7/18/2026

Usage

1 downloads Β· 1 views

File structure

πŸ“ references/

πŸ“„ scoring-templates.md

πŸ“„ SKILL.md