community-management

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to run a shell command (ls) to inspect various hidden directories within the user's home folder (such as ~/.claude/skills/, ~/.agent/skills/, and ~/.agents/skills/). This is used to perform a 'companion check' to identify other installed skills.
  • [PROMPT_INJECTION]: The skill includes instructions that override standard agent behavior, such as mandating that every first response begins with a specific emoji (๐Ÿงข) and requiring the agent to automatically perform filesystem inspection upon activation.
  • [EXTERNAL_DOWNLOADS]: The documentation and skill instructions recommend downloading and installing additional code packages from the AbsolutelySkilled GitHub repository using the npx skills command.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit โ€” agent-trust-hub โ€” community-management