absolute-brainstorm
Fail
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to read and search sensitive files including ".env.local" and other environment configuration files. It also directs the agent to list contents of hidden configuration directories in the user's home directory such as "
/.claude/skills/", "/.agent/skills/", and "~/.agents/skills/", which may expose private configuration data. - [REMOTE_CODE_EXECUTION]: The skill logic and README documentation promote the execution of remote code through "npx" commands to install additional functionality from an external, non-trusted repository ("AbsolutelySkilled/AbsolutelySkilled"). This introduces a significant supply-chain risk if the external source is compromised.
- [PROMPT_INJECTION]: The skill uses strong, mandatory language like "You MUST use this before any creative work" and "ALWAYS enter plan mode" to override the agent's default behavior. It enforces a rigid "ultrathink" persona and "relentless interview" process that aims to control the agent's reasoning process and bypass standard interaction models.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform directory listings in user-level configuration folders ("ls ~/.claude/skills/" etc.) to check for installed skills, which is an unnecessary permission level for the stated purpose of brainstorming.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface for indirect prompt injection.
- Ingestion points: It performs deep scans of codebase files including "docs/", "README.md", "CLAUDE.md", "CONTRIBUTING.md", and git commit history.
- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions when reading these external files.
- Capability inventory: The skill has the ability to write to the filesystem ("docs/plans/") and execute terminal commands.
- Sanitization: There is no mention of sanitizing or validating the content read from the codebase before it is processed by the reasoning engine.
Recommendations
- AI detected serious security threats
Audit Metadata