find-skills

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the process of searching for and installing modular packages from an external ecosystem. It specifically references trusted repositories such as those provided by Anthropic and Vercel Labs.- [COMMAND_EXECUTION]: Instructs the agent on the use of standard ecosystem CLI tools (npx skills) for managing workflows and tools. These commands are part of the intended functionality for extending agent capabilities.- [PROMPT_INJECTION]: Identifies a potential surface for indirect prompt injection where the agent ingests data from search results and the skills.sh website. The skill mitigates this risk by providing explicit instructions to verify source reputation, installation counts, and GitHub stars before recommending or installing any package.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 10:36 AM
Security Audit — agent-trust-hub — find-skills