find-skills
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
npx skillscommand-line interface to perform search, installation, and management tasks for agent skills. - [EXTERNAL_DOWNLOADS]: Fetches skill metadata and packages from external sources including the
skills.shregistry and GitHub repositories, including those from trusted organizations like Vercel Labs. - [REMOTE_CODE_EXECUTION]: Facilitates the installation and potential execution of external code. While the instructions suggest using the
-yflag to skip tool-level confirmation, they include explicit steps for the agent to ask the user for permission before proceeding with any installation.
Audit Metadata