api-testing
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains instructions for the AI agent to execute shell commands (
ls) to inspect the contents of hidden directories such as~/.claude/skills/and~/.agent/skills/. This is designed to discover companion skills but results in scanning the local filesystem for information outside the immediate working directory. - [EXTERNAL_DOWNLOADS]: The documentation references an external installation command (
npx skills add AbsolutelySkilled/AbsolutelySkilled) that downloads and executes code from a remote source. - [PROMPT_INJECTION]: The skill defines patterns for processing and asserting on external API responses, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Data enters via API response bodies (e.g.,
res.bodyinsupertest) and GraphQL operation results. - Boundary markers: The provided code examples do not include delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The agent possesses capabilities for shell command execution, filesystem access, and network operations.
- Sanitization: No sanitization or filtering of the incoming data is implemented in the provided test patterns.
Audit Metadata