wondelai-skills

Warn

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's metadata and body (upstream fields and SKILL.md) reference an external GitHub repository (https://github.com/wondelai/skills) as the source for the design skills it describes.\n- [REMOTE_CODE_EXECUTION]: The installation instructions recommend executing npx skills add wondelai/skills, which downloads and executes code from a remote third-party repository at runtime.\n- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to use shell execution (suggesting the ! prefix) to perform installation and verification tasks such as ls ~/.design-agent-skills/skills/.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 27, 2026, 08:25 AM
Security Audit — agent-trust-hub — wondelai-skills