search-skill

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a workflow for searching and reading external skill definitions (SKILL.md files) from GitHub and other curated registries. This behavior is consistent with its stated purpose of skill discovery and evaluation.
  • [SAFE]: Security is prioritized by instructions that forbid the generation of installation commands, requiring the agent to instead provide study, adapt, or ignore recommendations. This prevents the automatic execution of potentially untrusted code.
  • [SAFE]: No hardcoded credentials, sensitive file access patterns, or unauthorized persistence mechanisms were detected. The use of WebSearch and WebFetch tools is appropriately scoped to public repositories and known technology marketplaces.
  • [SAFE]: The skill provides a detailed quality rubric (toothbrush filter) that encourages the evaluation of external code based on technical merits such as token efficiency and single responsibility, rather than just descriptive metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:17 AM
Security Audit — agent-trust-hub — search-skill