browse-and-evaluate

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill promotes a security-first approach to skill management by instructing the agent to use --dry-run and --limit flags. This prevents excessive data ingestion and allows for human-in-the-loop verification before installation.\n- [EXTERNAL_DOWNLOADS]: The skill enables the retrieval of external skill packages from a remote catalog. The instructions mitigate associated risks by guiding the user to verify reachable sources during the evaluation phase.\n- [INDIRECT_PROMPT_INJECTION]: The preview workflow processes third-party skill content which could contain malicious instructions. The skill explicitly notes that the CLI tool performs sanitization to strip these patterns, reducing the surface for injection attacks.\n- [COMMAND_EXECUTION]: The workflow involves executing CLI commands through npx. These commands are specific to the skill's stated purpose of catalog exploration and management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:33 AM
Security Audit — agent-trust-hub — browse-and-evaluate