claude-pm-skills

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading a package from an unverified GitHub repository ('pratikshadake/claude-product-management-skills') using npx.
  • [COMMAND_EXECUTION]: The instructions explicitly guide the agent to use the '!' prefix to execute shell commands for installation within the agent environment.
  • [REMOTE_CODE_EXECUTION]: The installation process involves 'npx skills add', which fetches and runs external code from the network at runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — claude-pm-skills