skills/joker-ye/skills/find-skills/Gen Agent Trust Hub

find-skills

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using npx skills to search for, check, and update agent extensions. It includes instructions for global installations (-g) and bypassing confirmation prompts (-y).\n- [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing external packages from GitHub and other sources via the Skills CLI. It specifically mentions using resources from well-known repositories like those maintained by Vercel Labs.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from search results and uses it to execute installation commands.\n
  • Ingestion points: Data enters the agent's context through the output of the npx skills find command, which lists available packages based on a search query.\n
  • Boundary markers: The instructions do not define delimiters or provide warnings to the agent to ignore potentially malicious instructions embedded in skill descriptions or metadata returned by the search command.\n
  • Capability inventory: The agent has the capability to run shell commands and install software globally without user intervention using the -y flag.\n
  • Sanitization: No mechanism is described to validate or sanitize the package names or repository paths returned by the search tool before they are passed to the installation command.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:44 AM
Security Audit — agent-trust-hub — find-skills