find-skills

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of agent skills from external GitHub repositories and the skills.sh registry using the npx skills add command.
  • [REMOTE_CODE_EXECUTION]: The skill specifically directs the agent to use the -y flag during installation, which bypasses user confirmation and allows for the silent execution of remote code contained within third-party packages.
  • [COMMAND_EXECUTION]: The skill relies on the execution of shell commands via npx to perform search, installation, and management tasks within the local system environment.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from npx skills find output (ingestion point) without boundary markers or sanitization; this creates an attack surface where malicious package metadata from external sources could influence agent behavior while the agent has shell execution capabilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — find-skills