developer-experience
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's instructions in
SKILL.mdexplicitly direct the agent to run a shell command (ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/ 2>/dev/null) to probe for other installed skills. This allows the agent to explore the user's filesystem and identify specific software configurations, including hidden directories in the user home folder. - [EXTERNAL_DOWNLOADS]: The skill prompts the user and the agent to install additional components using
npx skills add AbsolutelySkilled/AbsolutelySkilled. This pattern involves fetching code from a remote third-party source and executing it locally. - [REMOTE_CODE_EXECUTION]: By recommending the use of
npxto add new skills from an external repository, the skill facilitates a path for remote code to be downloaded and executed on the user's machine without verifying the integrity or source beyond the repository name.
Audit Metadata