frontend-developer

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains explicit instructions in SKILL.md for the AI agent to execute a shell command to probe the user's local directory for other installed skills. This behavior constitutes environment reconnaissance and unauthorized access to the agent's internal configuration paths.
  • Evidence: check which companion skills are installed by running ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/ 2>/dev/null.
  • [EXTERNAL_DOWNLOADS]: The documentation encourages the execution of remote code from an external source via npx during the installation process.
  • Evidence: npx skills add AbsolutelySkilled/AbsolutelySkilled --skill frontend-developer.
  • [PROMPT_INJECTION]: The skill attempts to override the agent's standard communication style by mandating a specific emoji prefix for all initial responses, which serves as a behavioral constraint.
  • Evidence: When this skill is activated, always start your first response with the ๐Ÿงข emoji.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” frontend-developer