sales-third-party
Warn
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions and shell commands to fetch content from multiple third-party GitHub repositories. These external sources are not part of the author's own infrastructure or recognized trusted organizations. Affected repositories include:
coreyhaines31/marketingskillsresciencelab/opc-skillsaaron-he-zhu/seo-geo-claude-skillsjimliu/baoyu-skillssupercent-io/skills-templatewshobson/agentscalm-north/seojuice-skillsstarchild-ai-agent/official-skillsinferen-sh/skills- [COMMAND_EXECUTION]: The skill includes pre-formatted shell commands (
npx skills add) and instructs the agent to "help them [the user] install what they need." If the agent executes these commands, it will download and install external code and configurations to the local environment from the unverified sources listed above.
Audit Metadata