skillsman-manage

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the skillsman CLI to manage the lifecycle of project skills, including subcommands like init, add, remove, and doctor.
  • [EXTERNAL_DOWNLOADS]: The management process relies on npx skills, which fetches and executes packages from the npm registry to perform the actual skill installations.
  • [COMMAND_EXECUTION]: The instructions reference a specific local binary path (/Users/yatmn/Projects/skillsman/bin/skillsman) as a fallback if the skillsman command is not in the system PATH. This path is identified as a resource corresponding to the skill's author ('YatMn').
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:33 AM
Security Audit — agent-trust-hub — skillsman-manage