framer-motion-skills
Warn
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install additional functionality from a third-party repository (
https://github.com/C-Jeril/framer-motion-skills) using thenpx skills addcommand. This introduces unverifiable code from a source not recognized as a trusted vendor. - [COMMAND_EXECUTION]: The documentation promotes the use of the
!command prefix (e.g.,! npx skills add ...), which is a specific syntax in some agent environments to trigger shell command execution. This pattern facilitates the execution of arbitrary external scripts with potentially elevated privileges.
Audit Metadata