find-skills
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to interpolate user-provided search queries directly into shell commands, such as
npx skills find [query]. This pattern introduces a potential command injection vulnerability if the user input is not properly sanitized before being passed to the shell. - [COMMAND_EXECUTION]: In the 'Offer to Install' section, the skill recommends executing the installation command with the
-yflag (e.g.,npx skills add <owner/repo@skill> -g -y). This flag bypasses confirmation prompts, which suppresses the user's ability to review and approve the installation of external code, increasing the risk of automated execution of malicious packages if the agent is misled. - [COMMAND_EXECUTION]: The skill's primary function is to browse and install external executable packages from third-party sources (GitHub repositories). While the instructions advise checking for install counts and source reputation, the inherent nature of the tool involves the execution of remote code on the local system.
Audit Metadata