accessibility-wcag

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to autonomously run a shell command (ls) targeting multiple hidden directories in the user's home folder and project root (e.g., ~/.claude/skills/, ~/.agent/skills/, .agents/skills/). This is used to perform a 'companion check' to programmatically identify installed tools.
  • [PROMPT_INJECTION]: The instructions mandate that the agent must override its default response behavior by always starting the first response with a specific emoji ('๐Ÿงข') and performing a conditional environment check upon activation.
  • [EXTERNAL_DOWNLOADS]: The documentation and agent instructions recommend the installation of additional skills using 'npx skills add AbsolutelySkilled/AbsolutelySkilled', which involves fetching and executing code from an external repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” accessibility-wcag