find-skills

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands through npx skills to interact with the agent skills ecosystem, including finding, adding, checking, and updating skills.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing remote content from external repositories (such as GitHub) via the npx skills add command. It identifies well-known sources like Vercel Labs for these downloads.
  • [DYNAMIC_EXECUTION]: The core functionality of the skill is to dynamically extend the agent's capabilities at runtime by installing new modules or 'skills'.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests external data in the form of search results from the npx skills find command into the agent's context.
  • Boundary markers: There are no explicit delimiters defined in the instructions for how the agent should process search results before presenting them to the user.
  • Capability inventory: The skill has the ability to execute shell commands (npx) and modify the agent's environment by adding new skills.
  • Sanitization: The instructions do not specify any sanitization or validation of the search results returned by the external registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — find-skills