skills/google/capsem/meta-find-skills/Gen Agent Trust Hub

meta-find-skills

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • External Code Installation: The skill provides instructions for the agent to install third-party capabilities using the npx skills add command. This involves executing code from external GitHub repositories. While the skill outlines a verification process—checking install counts, source reputation, and GitHub stars—the execution of external scripts is a security consideration for automated environments.
  • Automated Command Execution: The usage of the -y flag in the installation commands (npx skills add <package> -y) allows the agent to skip interactive confirmation prompts. Bypassing user review during the installation of new software or skills reduces oversight and is a point for review in security-sensitive workflows.
  • Indirect Prompt Injection Surface: The skill functions by ingesting search results from an external registry (skills.sh). This creates a surface where malicious metadata or skill names could potentially influence the agent's behavior. The skill acknowledges this by including a 'Verify Quality' step, providing a mandatory evidence chain: (1) Ingestion point is the npx skills find output, (2) No explicit boundary markers are present in the command output results, (3) Capabilities include full package installation and execution via the CLI, and (4) Sanitization is performed through the agent's manual verification of source metrics and reputations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — meta-find-skills