google-fonts-skill
Warn
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
google-fonts-mcppackage from an external registry. The package is maintained by an unverified third-party account (sliday) and is not hosted by a verified or well-known organization. - [REMOTE_CODE_EXECUTION]: The use of
uvx google-fonts-mcpinvolves fetching and executing code from a remote repository at runtime, which constitutes an unverifiable dependency from an unknown source. - [COMMAND_EXECUTION]: The installation instructions guide the user to execute shell commands (
claude mcp add) that register an external MCP server and run its binaries on the local system with the user's privileges.
Audit Metadata