agent-skills-manager
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: Includes a bootstrap installation command that downloads a script from the vendor's GitHub repository (ravnhq/ai-toolkit) and pipes it to the shell for immediate execution to set up the CLI tool.\n- [COMMAND_EXECUTION]: Uses the Bash tool to execute various corvus CLI commands for installing, searching, and managing AI skills.\n- [COMMAND_EXECUTION]: Directs the agent to modify or source shell configuration files (e.g., ~/.zshrc, ~/.bashrc) to update the PATH environment variable and enable shell completions for the corvus utility.\n- [EXTERNAL_DOWNLOADS]: Fetches the corvus installer and skill updates from the author's official GitHub repository.
Audit Metadata