customer-research

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform silent filesystem discovery using ls on multiple paths (e.g., ~/.claude/skills/, ~/.agent/skills/) to fingerprint other installed skills for its 'Companion check' feature. The use of 2>/dev/null in the command suppresses error reporting, which can mask the discovery activity from the user.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and process untrusted external data, such as customer survey verbatims, interview transcripts, and social mentions, without providing the agent with boundary markers or instructions to treat this content as untrusted.
  • Ingestion points: The skill processes survey data, interview transcripts, and 'Voice of Customer' (VoC) data as described in SKILL.md and the methodology files in references/.
  • Boundary markers: Absent. The instructions do not specify delimiters or 'ignore embedded instructions' warnings for external data.
  • Capability inventory: The agent typically has access to shell execution and file system tools which could be targeted by instructions hidden in customer data.
  • Sanitization: Absent. No validation or escaping of external content is recommended before processing.
  • [EXTERNAL_DOWNLOADS]: The documentation promotes the installation of the skill and its companions via npx skills add AbsolutelySkilled/AbsolutelySkilled, which downloads and executes code from a remote repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — customer-research