skills-manager

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using npx skills for searching and adding extensions. It also references a specific environment variable $CHERRY_STUDIO_BUN_PATH for alternative execution.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the download of the skills package from the NPM registry during runtime via the npx command.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of third-party code from GitHub repositories (e.g., npx skills add <owner/repo>). It correctly identifies that these skills have full permissions and instructs the agent to provide source links, safety warnings, and require manual user confirmation before the installation proceeds.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 01:57 PM
Security Audit — agent-trust-hub — skills-manager