find-skills
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from an external search ecosystem and uses it to propose or execute agent actions. Ingestion points: Output from the npx skills find command as described in SKILL.md. Boundary markers: No explicit delimiters or instructions are provided to the agent to treat search results as untrusted content. Capability inventory: The agent is instructed to use npx skills add -g -y (SKILL.md), which allows for global installation and execution of external packages while skipping user confirmation. Sanitization: There is no evidence of filtering or validation of the package names or metadata returned by search commands.
- [REMOTE_CODE_EXECUTION]: The skill documents and encourages the installation of external code packages using the npx skills add command. This mechanism downloads and integrates external scripts from repositories into the local environment.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands using npx, including searching for, adding, and updating skills.
Audit Metadata