typescript
Fail
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends installing an additional skill from an untrusted GitHub repository (
wshobson/agents) using thenpx skills addcommand. This represents a risk where the agent is instructed to fetch and execute instructions and scripts from a source not managed by the author or a trusted vendor.\n- [COMMAND_EXECUTION]: The documentation suggests the use of the--dangerously-allow-all-buildsflag withpnpm installfor CI environments. This flag disables critical security mechanisms in pnpm v10 that prevent the execution of unreviewed and potentially malicious lifecycle scripts from dependencies.\n- [EXTERNAL_DOWNLOADS]: The skill references an external repository (https://github.com/wshobson/agents) for extending functionality. This source is not categorized as a trusted organization or well-known service, presenting an unverified external dependency.
Recommendations
- AI detected serious security threats
Audit Metadata