find-skills
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands through
npx skillsto interact with the agent skills ecosystem, including finding, adding, checking, and updating skills. - [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing remote content from external repositories (such as GitHub) via the
npx skills addcommand. It identifies well-known sources like Vercel Labs for these downloads. - [DYNAMIC_EXECUTION]: The core functionality of the skill is to dynamically extend the agent's capabilities at runtime by installing new modules or 'skills'.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests external data in the form of search results from the
npx skills findcommand into the agent's context. - Boundary markers: There are no explicit delimiters defined in the instructions for how the agent should process search results before presenting them to the user.
- Capability inventory: The skill has the ability to execute shell commands (
npx) and modify the agent's environment by adding new skills. - Sanitization: The instructions do not specify any sanitization or validation of the search results returned by the external registry.
Audit Metadata