acquiring-skills
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates downloading content from several external sources, including GitHub, the Hermes Skills Hub (NousResearch), and the ClawHub community registry. These sources are recognized as trusted organizations or well-known services within the agent ecosystem.\n- [COMMAND_EXECUTION]: Provides instructions for using shell commands such as
git clone,cp, andrm, along with environment-specific CLI tools likeletta,hermes, andclawhubto manage skill lifecycle and installation.\n- [REMOTE_CODE_EXECUTION]: The skill is designed to install other skills that may contain executable scripts (Python, TypeScript, Bash). The instructions include explicit safety warnings to inspect all scripts and verify network or file operations before execution.\n- [INDIRECT_PROMPT_INJECTION]: As a loader for external instructions and code, this skill creates an attack surface for indirect prompt injection from downloaded content. It mitigates this risk by documenting verification procedures and requiring user approval for untrusted sources.
Audit Metadata