data-warehousing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands (ls) to check for the presence of recommended companion skills in local configuration directories (e.g., ~/.claude/skills/).
  • [EXTERNAL_DOWNLOADS]: The skill documentation describes how to install additional components using the npx skills add command from the AbsolutelySkilled repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a "Companion check" logic where the agent processes the output of local directory listings to make installation recommendations. This creates a surface where the agent's behavior is influenced by the contents of the local filesystem.
  • Ingestion points: The output of ls commands targeting various skill directories mentioned in SKILL.md.
  • Boundary markers: No specific delimiters or "ignore" instructions are present for the filesystem data.
  • Capability inventory: The agent has the capability to list directories and execute package-related commands (npx).
  • Sanitization: No explicit sanitization or validation of the directory listing output is defined before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — data-warehousing