developer-experience

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's instructions in SKILL.md explicitly direct the agent to run a shell command (ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/ 2>/dev/null) to probe for other installed skills. This allows the agent to explore the user's filesystem and identify specific software configurations, including hidden directories in the user home folder.
  • [EXTERNAL_DOWNLOADS]: The skill prompts the user and the agent to install additional components using npx skills add AbsolutelySkilled/AbsolutelySkilled. This pattern involves fetching code from a remote third-party source and executing it locally.
  • [REMOTE_CODE_EXECUTION]: By recommending the use of npx to add new skills from an external repository, the skill facilitates a path for remote code to be downloaded and executed on the user's machine without verifying the integrity or source beyond the repository name.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — developer-experience