third-party-skills

Warn

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute logic from third-party GitHub accounts (coreyhaines31/marketingskills, resciencelab/opc-skills) using the npx skills add command. This pattern facilitates the execution of remote code that has not been audited or verified by a recognized authority.\n- [EXTERNAL_DOWNLOADS]: The skill directs the system to fetch resources from unverified external domains and individual user repositories, which increases exposure to supply chain risks or malicious package substitution.\n- [COMMAND_EXECUTION]: The documentation includes shell commands that, when executed, perform network operations and local file system modifications to integrate external modules into the agent's environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 24, 2026, 12:06 PM