use-skill
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the fetching and dynamic execution of remote skill definitions. It mitigates associated risks by requiring explicit user confirmation before any tool calls from the fetched content are executed and by enforcing a strict hard-block list on high-risk commands.
- [EXTERNAL_DOWNLOADS]: Fetches skill metadata and instruction files from well-known services, specifically GitHub (api.github.com, raw.githubusercontent.com) and the skills.sh search API.
- [COMMAND_EXECUTION]: Utilizes curl and jq to resolve repository versions via commit SHAs and to retrieve remote content for ephemeral execution.
- [INDIRECT_PROMPT_INJECTION]: As a harness for third-party content, the skill proactively manages injection risks. Ingestion points occur via curl fetches of remote SKILL.md files. Boundary markers are established by instructing the agent to wrap untrusted content in dedicated XML-style tags. The capability inventory includes network retrieval and workflow execution. Sanitization is enforced through a mandatory pre-execution confirmation step and a comprehensive hard-block list that forbids privilege escalation, sensitive file access, and persistent modifications to the host system.
Audit Metadata