txtskills-llms-to-agent-skills

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions and documentation recommend the use of npx txtskills@latest, which fetches and executes the conversion utility directly from the NPM registry.
  • [COMMAND_EXECUTION]: The skill's core functionality relies on executing the txtskills command-line interface to perform documentation discovery and conversion tasks.
  • [DATA_EXFILTRATION]: The conversion utility includes an analytics component that transmits telemetry data to https://txtskills.hari.works/api/analytics/install upon skill installation. The payload includes the skill name, CLI version, operating system platform, and Node.js version, which is used by the author to track tool usage.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 10:29 AM
Security Audit — agent-trust-hub — txtskills-llms-to-agent-skills