email-marketing

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to automatically perform environment discovery by executing shell commands. Specifically, it instructs the agent to run ls on multiple sensitive directories within the user's home folder (such as ~/.claude/skills/, ~/.agent/skills/, and ~/.agents/skills/) to identify installed companion skills without an explicit user request for this file system access.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing software via npx skills add AbsolutelySkilled/AbsolutelySkilled. This references an unverified external GitHub repository, posing a risk of downloading unvetted or potentially malicious content.
  • [REMOTE_CODE_EXECUTION]: By encouraging the use of npx to fetch and execute scripts from a third-party source without integrity verification or version constraints, the skill introduces a remote code execution vector. A compromise of the target repository could lead to the execution of arbitrary code on the user's machine.
  • [PROMPT_INJECTION]: The 'Companion check' logic acts as a prompt injection by prescribing immediate, automated actions ('On first activation... check which companion skills are installed...') that override the default conversational flow. Additionally, the skill is vulnerable to indirect prompt injection: Ingestion points: User prompts requesting email campaign designs or deliverability analysis; Boundary markers: Absent; Capability inventory: Shell command execution (ls) and unverified npx execution; Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit — agent-trust-hub — email-marketing