game-design-patterns
Warn
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The 'Companion check' section instructs the agent to silently scan the filesystem upon activation. It targets specific directories including hidden folders in the user's home directory (~/.claude/skills/, ~/.agent/skills/, etc.) using the 'ls' command to gather information about the environment and other installed extensions without user consent.\n- [REMOTE_CODE_EXECUTION]: The skill encourages the installation of further external components from an untrusted third-party repository using 'npx skills add'. This action facilitates the download and execution of remote code on the host machine.\n- [EXTERNAL_DOWNLOADS]: The instruction set directs the agent to fetch and install additional skill packages from the AbsolutelySkilled organization, which is not an established trusted vendor.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes a pattern where the untrusted state of the local filesystem (the presence or absence of specific files) directly influences the agent's prompt output and subsequent execution of installation commands.\n
- Ingestion points: Output of the 'ls' command on local skill directories as specified in SKILL.md.\n
- Boundary markers: No delimiters or safety instructions are provided to separate the command output from the agent's logic.\n
- Capability inventory: The skill possesses shell execution capabilities for both reconnaissance ('ls') and package management ('npx').\n
- Sanitization: The skill does not perform any validation or filtering on the filesystem data before processing it into recommendations.
Audit Metadata