find-tool

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and does not contain malicious code, obfuscation, or unauthorized network operations. Its design focuses on assisting users with development task research and tool selection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external, untrusted sources such as package registries (npm, PyPI), GitHub repositories, and general web search results. This constitutes an indirect prompt injection surface where malicious content in an external package description could attempt to influence the agent's behavior. The skill mitigates this risk by providing a 'Red Flags' section and instructing the agent to prioritize authoritative sources (official docs, security advisories) over secondary comparisons.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 12:28 PM
Security Audit — agent-trust-hub — find-tool