skills/agentskillexchange/skills/Run independent multi-agent build and review flows with OPC/Gen Agent Trust Hub
Run independent multi-agent build and review flows with OPC
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing an external Node.js package (@touchskyer/opc) and cloning a repository from GitHub (iamtouchskyer/opc). These resources originate from an individual publisher rather than a verified organization.\n- [REMOTE_CODE_EXECUTION]: The package installation includes a post-installation script that automatically copies files to the user's home directory (~/.claude/skills/opc/). Such automated scripts can execute arbitrary code during the installation process.\n- [METADATA_POISONING]: The skill metadata includes a 'verification' field asserting that the content has been 'security_reviewed'. Users should ignore this claim as it is self-reported and cannot be independently confirmed within the skill context.
Audit Metadata