data-viz-agent

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install its full logic from an external third-party GitHub repository (https://github.com/rohitg00/awesome-claude-code-toolkit) that is not recognized as a trusted vendor.
  • [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using grep to inspect local files in the user's home directory (~/.agents/skills/...) and npx to initiate the installation process.
  • [REMOTE_CODE_EXECUTION]: The installation mechanism (npx skills add) fetches and installs executable content from a remote source, which constitutes remote code execution from an unverified repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — data-viz-agent