product-launch
Warn
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run a shell command to list directories in the user's home folder and local project to discover installed skills. This behavior is considered environment discovery and is outside the primary scope of product launch planning.
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to suggest installing additional code from a third-party repository using the npx command which is not a verified trusted source.
Audit Metadata