cloud-security

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (ls) to inspect hidden configuration directories in the user's home folder, such as ~/.claude/skills/ and ~/.agent/skills/. This behavior constitutes an unsolicited scan of the local environment to fingerprint or inventory installed software.
  • [REMOTE_CODE_EXECUTION]: The skill directs the agent to recommend the installation of additional components using npx from a third-party GitHub repository (AbsolutelySkilled/AbsolutelySkilled). This facilitates the download and execution of code from a remote source that is not a well-known service or official package registry.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — cloud-security