find-skills

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx skills find and npx skills add to interact with a centralized registry at skills.sh. These operations target a well-known service for skill management.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use npx commands. These are legitimate uses of the Skills CLI for package discovery and installation within the intended ecosystem.
  • [DATA_EXFILTRATION]: No sensitive data access or unauthorized network transmissions were detected. Network operations are limited to searching and installing packages from public registries.
  • [PROMPT_INJECTION]: No attempts to bypass safety filters or override system instructions were found. The skill maintains professional boundaries and provides clear, task-oriented guidance.
  • [REMOTE_CODE_EXECUTION]: While the skill involves installing third-party packages, it includes explicit safety guidelines for the agent to verify reputation (install count, source reputation, and GitHub stars) before recommending or installing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:27 PM
Security Audit — agent-trust-hub — find-skills