find-skill

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs network operations to several third-party, non-whitelisted domains (claudemarketplaces.com, skillsmp.com, skillhub.club, lobehub.com, mcpmarket.com, claudeskills.info, agentskills.io) to fetch search results and skill metadata.
  • [EXTERNAL_DOWNLOADS]: The skill fetches and processes content from multiple community marketplaces. These sources host unverified third-party content, which the agent is instructed to ingest and summarize. The instructions also direct users to installation paths for these external plugins.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external marketplaces.
  • Ingestion points: Skill descriptions and SKILL.md files fetched from community marketplaces and repositories via web search and retrieval tools as described in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify delimiters or provide warnings for the agent to ignore instructions embedded within the retrieved content.
  • Capability inventory: The skill utilizes the agent's web browsing and content retrieval capabilities. If the agent environment includes tools for file system access or command execution, an injection could potentially target those capabilities.
  • Sanitization: Absent. There is no evidence of validation or filtering of the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 07:43 AM
Security Audit — agent-trust-hub — find-skill