skill-finder

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local searches using the grep utility on the references/official-skills.md file to match user requirements against known skills.\n- [EXTERNAL_DOWNLOADS]: The skill suggests a fallback to npx skills find, which involves downloading and executing the skills package from the npm registry. This package is managed by Vercel Labs, a well-known and established organization.\n- [PROMPT_INJECTION]: The skill reads from an extensive local reference file (references/official-skills.md) containing descriptions and metadata from over 1184+ community and official sources. This presents a potential surface for indirect prompt injection if the source data contains adversarial instructions meant to influence the agent's behavior during processing.\n
  • Ingestion points: references/official-skills.md processed via grep and read by the agent.\n
  • Boundary markers: None present to distinguish between search text and instructions.\n
  • Capability inventory: Local file reading, grep execution, and npx package execution.\n
  • Sanitization: No explicit sanitization or filtering of the content within the reference file before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:32 PM
Security Audit — agent-trust-hub — skill-finder