find-skills
Warn
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands via
npx skillsto interact with a package ecosystem, performing keyword searches and managing skill installations. - [EXTERNAL_DOWNLOADS]: Facilitates downloading agent skills from remote sources, specifically targeting GitHub repositories and the
skills.shregistry. - [REMOTE_CODE_EXECUTION]: Explicitly instructs the agent to use the
-yflag when adding skills (npx skills add <package> -y). This flag bypasses interactive confirmation prompts, allowing for the silent installation and subsequent execution of third-party code. - [PROMPT_INJECTION]: The skill's workflow for finding and installing external packages creates a surface for indirect prompt injection, where malicious package metadata could influence agent actions.
- Ingestion points: User search queries processed via
npx skills find. - Boundary markers: None identified.
- Capability inventory: Subprocess execution for package discovery (
npx skills find) and installation (npx skills add). - Sanitization: No input validation or sanitization of search queries or package names is specified.
Audit Metadata