customer-research
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform silent filesystem discovery using
lson multiple paths (e.g.,~/.claude/skills/,~/.agent/skills/) to fingerprint other installed skills for its 'Companion check' feature. The use of2>/dev/nullin the command suppresses error reporting, which can mask the discovery activity from the user. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and process untrusted external data, such as customer survey verbatims, interview transcripts, and social mentions, without providing the agent with boundary markers or instructions to treat this content as untrusted.
- Ingestion points: The skill processes survey data, interview transcripts, and 'Voice of Customer' (VoC) data as described in
SKILL.mdand the methodology files inreferences/. - Boundary markers: Absent. The instructions do not specify delimiters or 'ignore embedded instructions' warnings for external data.
- Capability inventory: The agent typically has access to shell execution and file system tools which could be targeted by instructions hidden in customer data.
- Sanitization: Absent. No validation or escaping of external content is recommended before processing.
- [EXTERNAL_DOWNLOADS]: The documentation promotes the installation of the skill and its companions via
npx skills add AbsolutelySkilled/AbsolutelySkilled, which downloads and executes code from a remote repository.
Audit Metadata