growth-hacking

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to automatically execute a shell command to scan the user's home directory for other installed AI agent skills upon activation.\n
  • Evidence: ls ~/.claude/skills/ ~/.agent/skills/ ~/.agents/skills/ .claude/skills/ .agent/skills/ .agents/skills/ 2>/dev/null\n- [REMOTE_CODE_EXECUTION]: The skill directs the agent to suggest installing additional dependencies via the npx package runner from an unverified source.\n
  • Evidence: npx skills add AbsolutelySkilled/AbsolutelySkilled --skill <name>\n- [EXTERNAL_DOWNLOADS]: The skill promotes the download and installation of tools from 'AbsolutelySkilled', which is not a verified or trusted vendor source.\n
  • Evidence: Installation instructions point to AbsolutelySkilled/AbsolutelySkilled and the domain absolutelyskilled.pro.\n- [PROMPT_INJECTION]: The skill contains instructions that override the agent's standard behavior by forcing automated system checks and mandatory response formatting (emoji usage) immediately upon activation.\n
  • Evidence: Mandatory requirement to start the first response with the ๐Ÿงข emoji and perform an automated ls check.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” growth-hacking