find-skills
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Package Installation and Command Execution: The skill utilizes the
npx skillscommand to search for and install external code modules. This is the core intended functionality of the skill, providing a way to extend the agent's capabilities through a controlled package manager. The instructions explicitly recommend using the-yflag for automated installation, which increases the agent's autonomy when managing its environment. - External Resource Acquisition: The skill is designed to fetch and install packages from remote repositories. To manage the associated risks, the instructions provide a framework for evaluating external content, such as checking installation counts, repository stars, and the reputation of the source organization.
- Indirect Prompt Injection Surface: Because this skill processes search results and metadata from a public ecosystem, it may encounter untrusted content within skill descriptions. The skill includes specific steps for the agent to verify the quality and source of a skill before presenting it to the user or performing an installation, which helps mitigate the risk of following instructions embedded in third-party metadata.
Audit Metadata