alibabacloud-find-skills

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs HTTP requests to https://agentexplorer.aliyuncs.com to search for, browse, and retrieve the content of agent skills. This is a vendor-controlled domain (Alibaba Cloud) and is used appropriately for its stated purpose.
  • [COMMAND_EXECUTION]: The skill utilizes curl (and powershell with curl.exe on Windows) to interact with the AgentExplorer API. It also uses npx skills add and npx clawhub install to install discovered skills. These operations are essential to the skill's primary functionality and target vendor-scoped packages.
  • [PROMPT_INJECTION]: A static analysis alert for potential action concealment was evaluated and determined to be a false positive. The content in references/acceptance-criteria.md correctly distinguishes between 'Correct' and 'Incorrect' patterns to guide the agent toward modern API-based workflows and away from outdated CLI methods.
  • [SAFE]: The skill adheres to best practices by using vendor-managed infrastructure and established package installation mechanisms. No attempts to exfiltrate data, bypass security controls, or execute obfuscated code were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:12 AM
Security Audit — agent-trust-hub — alibabacloud-find-skills