agent-starter-kit

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes an automation script (install.sh) designed to streamline the configuration of the agent by executing shell commands to install dependencies.
  • [EXTERNAL_DOWNLOADS]: The installer fetches multiple third-party skills using the npx skills utility from various public GitHub repositories, including those for behavior guidelines (karpathy-guidelines), design intelligence (ui-ux-pro-max), and specific formatting (caveman).
  • [EXTERNAL_DOWNLOADS]: Fetches core components and meta-skills from Vercel Labs' official GitHub repositories.
  • [EXTERNAL_DOWNLOADS]: Installs several plugins and Model Context Protocol (MCP) servers from the official Claude plugin marketplace and established community sources to extend functionality for tasks like browser automation and GitHub management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 05:38 PM
Security Audit — agent-trust-hub — agent-starter-kit