txtskills-llms-to-agent-skills
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions and documentation recommend the use of
npx txtskills@latest, which fetches and executes the conversion utility directly from the NPM registry. - [COMMAND_EXECUTION]: The skill's core functionality relies on executing the
txtskillscommand-line interface to perform documentation discovery and conversion tasks. - [DATA_EXFILTRATION]: The conversion utility includes an analytics component that transmits telemetry data to
https://txtskills.hari.works/api/analytics/installupon skill installation. The payload includes the skill name, CLI version, operating system platform, and Node.js version, which is used by the author to track tool usage.
Audit Metadata