Is Skills CLI (npx skills) Safe to Use?

Is Skills CLI (npx skills) safe for your developer workspace? We review the security posture of Skills CLI (npx skills) using static code finding reports and independent partner audits, helping you make informed security decisions before running it with local CLI privileges.

Data from the 2026-09-07 edition | methodology pulse-v1

SkillPilot Security Verdict

Ecosystem Status
Trust pending
Scanned on: 2026-09-07T03:52:50.764Z

Partner Audits & Risk Assessment

ProviderStatusRisk LevelSummaryAudited At
Gen Agent Trust HubpassSAFEThis skill facilitates the discovery and installation of agent capabilities via a package management utility. It uses standard command-line tools to interact with a centralized registry, which is the primary intended purpose of the skill. All external references are associated with the vendor's own infrastructure or well-known services.2026-03-15T07:01:45.434Z
Socketpass-No alerts2026-03-18T16:47:53.829Z
SnykwarnMEDIUMRisk: MEDIUM · 1 issue2026-03-15T06:58:54.797434+00:00
RunlayerpassNONE1 file scanned · No issues2026-03-14T07:45:27.566Z
ZeroLeakspassNONEScore: 93/100 · 2 sections analyzed2026-04-16T07:47:59.444Z

Static Code Scan Findings

No high-severity static code scan findings identified in the repository.

Security Disclaimer

The safety reports and verdicts displayed on SkillPilot represent static analysis and partner audit results as of the current database edition. This data does not constitute a formal security warranty. Software vulnerabilities are dynamic; you should always run third-party plugins and Model Context Protocol servers in isolated or sandboxed environments whenever possible.

Frequently Asked Questions

What does a trust-checked verdict mean?

A trust-checked verdict indicates that the tool has passed basic static analysis criteria and has no open critical alerts from partner audits or scanning software.

How often are these security scans performed?

Security scans and audit logs are updated daily in our database snapshots to reflect active changes and newly disclosed vulnerabilities.

Why should I sandbox MCP servers?

MCP servers execute with the same privileges as your local IDE or CLI assistant. Sandboxing prevents unauthorized operations like reading private SSH keys or deleting files.

How do I report a security issue for a tool?

You should report vulnerabilities directly to the project's repository maintainers. The findings displayed here are compiled from public repositories and partner audits.