find-skills
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard shell utilities including
jqandgrepto search through local skill indices and markdown files. It also utilizesnpxto interact with the agent skills marketplace. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of external code via the
npx skills addcommand. This is the intended core functionality and is accompanied by explicit instructions to verify the source repository's activity and issue history before proceeding. - [PROMPT_INJECTION]: The skill processes content from local skill files and generated indices, which represents a surface for indirect prompt injection if those files were to contain malicious instructions.
- Ingestion points: Metadata from
skills/skill-index.jsonand content fromskills/*/SKILL.md. - Boundary markers: The skill does not currently utilize explicit delimiters when presenting or processing the content of discovered skills.
- Capability inventory: The skill has the ability to execute shell commands (
npx,jq,grep) and load other skills into the agent's environment using theSkill()constructor. - Sanitization: The skill relies on manual evaluation steps (prescribed in
evaluating-candidates.md) to mitigate risks rather than automated content sanitization.
Audit Metadata