project-skill-installer
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a 'Validation Before Execution' phase (L4) that requires explicit human-in-the-loop confirmation before any installation or configuration actions are performed.\n- [SAFE]: Instructions strictly enforce project-relative paths for all operations, explicitly rejecting global installation requests to maintain environment isolation and prevent unauthorized persistence.\n- [COMMAND_EXECUTION]: The skill identifies a dependency on 'find-skills' and provides the user with a specific command (
npx skills add find-skills -g -y) to run manually if prerequisites are missing, ensuring the user retains control over the execution environment.\n- [EXTERNAL_DOWNLOADS]: External references and best practices are linked to 'agentskills.io', which is the established documentation source for the skill framework being utilized.
Audit Metadata