distinctive-frontend
Warn
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install a package from the public NPM registry:
@bong/claude-frontend-skills. This package is not from a verified or trusted organization, posing a supply chain risk. - [COMMAND_EXECUTION]: The installation process involves executing shell commands (
npm install -g) which can run arbitrary pre-installation or post-installation scripts with global system permissions.
Audit Metadata