design-negotiation

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is a 'catalogue stub' designed to fetch additional content from an external source at 'github.com/Owl-Listener/designer-skills'.
  • [COMMAND_EXECUTION]: Provides specific shell commands using grep and npx to check local environment status and modify the system state by adding new skills.
  • [REMOTE_CODE_EXECUTION]: Instructions direct the agent to execute npx skills add, which downloads and runs external packages from the npm registry and the specified GitHub repository. This facilitates the execution of unverified remote code on the host machine.
  • [DYNAMIC_CONTEXT_INJECTION]: The documentation explicitly encourages the use of the ! command prefix (a feature of specific agent platforms like Claude Code) to execute these installation commands silently within the conversation, bypassing standard user interaction steps.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 01:27 PM
Security Audit — agent-trust-hub — design-negotiation