find-skills

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent on how to use the npx skills CLI. While this involves command execution, these are standard package management operations (find, add, update) for the agent ecosystem and are part of the skill's primary documented purpose.
  • [EXTERNAL_DOWNLOADS]: The skill references downloading and installing packages from external sources via npx skills add. However, it explicitly includes safety instructions for the agent, such as verifying install counts, source reputation (citing trusted organizations like Vercel and Anthropic), and repository stars before recommending or installing them.
  • [REMOTE_CODE_EXECUTION]: Installing agent skills inherently involves adding new capabilities to the environment. The skill mitigates risks by instructing the agent to prefer well-known, high-install-count sources and to treat unknown authors with skepticism. References to external URLs (skills.sh) and organizations (Vercel, Anthropic) target well-known services and trusted entities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 09:20 PM
Security Audit — agent-trust-hub — find-skills