find-skills

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell utilities including jq and grep to search through local skill indices and markdown files. It also utilizes npx to interact with the agent skills marketplace.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of external code via the npx skills add command. This is the intended core functionality and is accompanied by explicit instructions to verify the source repository's activity and issue history before proceeding.
  • [PROMPT_INJECTION]: The skill processes content from local skill files and generated indices, which represents a surface for indirect prompt injection if those files were to contain malicious instructions.
  • Ingestion points: Metadata from skills/skill-index.json and content from skills/*/SKILL.md.
  • Boundary markers: The skill does not currently utilize explicit delimiters when presenting or processing the content of discovered skills.
  • Capability inventory: The skill has the ability to execute shell commands (npx, jq, grep) and load other skills into the agent's environment using the Skill() constructor.
  • Sanitization: The skill relies on manual evaluation steps (prescribed in evaluating-candidates.md) to mitigate risks rather than automated content sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — find-skills