find-skills

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the npx skills command-line interface to perform search, installation, and management tasks for agent skills.
  • [EXTERNAL_DOWNLOADS]: Fetches skill metadata and packages from external sources including the skills.sh registry and GitHub repositories, including those from trusted organizations like Vercel Labs.
  • [REMOTE_CODE_EXECUTION]: Facilitates the installation and potential execution of external code. While the instructions suggest using the -y flag to skip tool-level confirmation, they include explicit steps for the agent to ask the user for permission before proceeding with any installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 03:36 AM