bombshell-dev-clack

Warn

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent or user to execute shell commands using npx -y skilld search to query local documentation and issues.
  • [REMOTE_CODE_EXECUTION]: The recommendation to use npx -y skilld triggers the automatic download and immediate execution of a package from the public npm registry at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill depends on an external utility (skilld) that is not part of the local skill distribution and is not identified as a standard or well-known development tool, creating a risk of executing unverified code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 3, 2026, 11:07 AM