find-skills
Warn
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of agent skills from external GitHub repositories and the skills.sh registry using the npx skills add command.
- [REMOTE_CODE_EXECUTION]: The skill specifically directs the agent to use the -y flag during installation, which bypasses user confirmation and allows for the silent execution of remote code contained within third-party packages.
- [COMMAND_EXECUTION]: The skill relies on the execution of shell commands via npx to perform search, installation, and management tasks within the local system environment.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from npx skills find output (ingestion point) without boundary markers or sanitization; this creates an attack surface where malicious package metadata from external sources could influence agent behavior while the agent has shell execution capabilities.
Audit Metadata