browse-and-evaluate
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill promotes a security-first approach to skill management by instructing the agent to use --dry-run and --limit flags. This prevents excessive data ingestion and allows for human-in-the-loop verification before installation.\n- [EXTERNAL_DOWNLOADS]: The skill enables the retrieval of external skill packages from a remote catalog. The instructions mitigate associated risks by guiding the user to verify reachable sources during the evaluation phase.\n- [INDIRECT_PROMPT_INJECTION]: The preview workflow processes third-party skill content which could contain malicious instructions. The skill explicitly notes that the CLI tool performs sanitization to strip these patterns, reducing the surface for injection attacks.\n- [COMMAND_EXECUTION]: The workflow involves executing CLI commands through npx. These commands are specific to the skill's stated purpose of catalog exploration and management.
Audit Metadata