google-fonts-skill

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the google-fonts-mcp package from an external registry. The package is maintained by an unverified third-party account (sliday) and is not hosted by a verified or well-known organization.
  • [REMOTE_CODE_EXECUTION]: The use of uvx google-fonts-mcp involves fetching and executing code from a remote repository at runtime, which constitutes an unverifiable dependency from an unknown source.
  • [COMMAND_EXECUTION]: The installation instructions guide the user to execute shell commands (claude mcp add) that register an external MCP server and run its binaries on the local system with the user's privileges.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — google-fonts-skill