find-skills
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill utilizes
npxto execute theskillkitCLI tool directly from the NPM registry. It further provides commands to install and execute code from remote GitHub repositories. - [EXTERNAL_DOWNLOADS]: Fetches executable skills and configurations from various external sources. These include official repositories from trusted organizations (Anthropic, Vercel, Supabase, Stripe) and various community-contributed repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays metadata from a marketplace containing over 400,000 third-party skills. This untrusted content could contain hidden instructions designed to manipulate the agent during the discovery process.
- Ingestion points: External search results from
npx skillkit findand marketplace browsing commands. - Boundary markers: None; the instructions do not define delimiters or specific warnings to ignore instructions embedded in search results.
- Capability inventory: The skill possesses shell execution capabilities (
npx) and the ability to perform file system writes during the installation of discovered skills. - Sanitization: There is no mention of sanitization, filtering, or validation of the external skill descriptions before they are processed by the agent.
Audit Metadata