absolute-simplify

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation and instructions recommend installing the skill and its companions using npx skills add AbsolutelySkilled/AbsolutelySkilled. This involves downloading and executing content from an external source.
  • [COMMAND_EXECUTION]: Upon activation, the skill performs an automated check for recommended companion skills by executing a shell command (ls) that scans several directory paths, including locations in the user's home directory (e.g., ~/.claude/skills/, ~/.agent/skills/).
  • [REMOTE_CODE_EXECUTION]: During the verification phase (Phase 6), the skill identifies and executes shell commands extracted from project configuration files such as package.json, Makefile, and pyproject.toml. This allows for the execution of arbitrary scripts or commands defined within the codebase the agent is processing.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by reading project-specific instructions from CLAUDE.md and related configuration files. The agent is explicitly instructed that these external instructions "override your opinions," which could lead to behavioral changes dictated by malicious content in the repository.
  • Ingestion points: Project configuration files (e.g., CLAUDE.md, package.json, Makefile) as described in Phase 2 of the skill instructions.
  • Boundary markers: No specific boundary markers or "ignore embedded instructions" warnings are used when the agent reads these files.
  • Capability inventory: The skill possesses file system write access (to apply code changes) and shell command execution capabilities (to run test and lint suites).
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the commands or instructions ingested from external project files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — absolute-simplify