ask-kent
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely informational, providing a 'main flow' map and decision logic for the agent to recommend other skills (like /orchestrate or /ship-pr) based on user situations.
- [EXTERNAL_DOWNLOADS]: The skill mentions installation instructions using 'npx skills add kentcdodds/kcd-skills'. This refers to the vendor's official repository and is presented as a manual step for the user rather than a hidden or automated execution by the agent.
- [INDIRECT_PROMPT_INJECTION]: The skill advises the agent to read other 'SKILL.md' files to verify information. While this defines how the agent should ingest repository data, the 'ask-kent' skill itself lacks any dangerous capabilities (such as file writing, shell execution, or network exfiltration) that could be exploited through this surface.
Audit Metadata