.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/env-and-assets-bootstrap/security
home/skills/env-and-assets-bootstrap/security
lllllllama avatar

env-and-assets-bootstrap — security audits

Passed all audits

Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.

  • Gen Agent Trust Hub

    pass

    This skill automates the setup of research environments and identifies asset requirements (like datasets and checkpoints) by parsing repository files. It uses standard tools such as conda and pip to manage dependencies. The primary security consideration is its inherent susceptibility to indirect prompt injection when processing untrusted third-party repositories, which could influence the setup plan or installation steps.

    Risk: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONMay 18, 2026Full report
  • Socket

    pass

    No alerts

    May 18, 2026Full report
  • Snyk

    pass

    Risk: LOW · No issues

    Risk: LOWMay 18, 2026Full report