affirmations

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests fetching and installing a related skill from an external repository. The resource 'inference-sh/skills@prompt-engineering' is an external third-party source that is not part of the trusted vendor or organization lists.\n- [REMOTE_CODE_EXECUTION]: The command 'npx skills add inference-sh/skills@prompt-engineering' provided in the documentation triggers the download and execution of code from the NPM registry. Running code from unverified external sources introduces supply chain risks, as the remote content is not audited for security.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 08:14 PM
Security Audit — agent-trust-hub — affirmations