hypercerts

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run npx skills add with the --yes flag, which automates the installation of external components by bypassing user confirmation prompts. It also includes a command to search the entire user home directory ($HOME) to locate specific skill metadata files.
  • [REMOTE_CODE_EXECUTION]: The skill is designed to install and then execute the instructions contained within external SKILL.md files downloaded from GitHub repositories.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content and configuration from multiple GitHub repositories, including those belonging to the hypercerts-org and GainForest organizations.
  • [PROMPT_INJECTION]: The workflow involves installing a focused skill and then reading its SKILL.md file to follow its instructions. This establishes a chain where external content from a repository can influence the agent's subsequent behavior without human review or sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:00 PM
Security Audit — agent-trust-hub — hypercerts