bombshell-dev-clack
Warn
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent or user to execute shell commands using
npx -y skilld searchto query local documentation and issues. - [REMOTE_CODE_EXECUTION]: The recommendation to use
npx -y skilldtriggers the automatic download and immediate execution of a package from the public npm registry at runtime. - [EXTERNAL_DOWNLOADS]: The skill depends on an external utility (
skilld) that is not part of the local skill distribution and is not identified as a standard or well-known development tool, creating a risk of executing unverified code.
Audit Metadata