coreyhaines-marketing

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install and execute code from an external, untrusted GitHub repository.
  • Evidence: npx skills add coreyhaines31/marketingskills in SKILL.md and stub.yaml.
  • Evidence: The source coreyhaines31 is an individual contributor and not a verified or trusted organization.
  • [COMMAND_EXECUTION]: The instructions explicitly guide the agent to use shell execution features to perform installations.
  • Evidence: The skill suggests sending a chat message starting with ! in Claude Code to execute the npx command.
  • Evidence: This pattern encourages the agent to bypass standard interaction boundaries to modify the local environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — coreyhaines-marketing