ios-swift

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the AI agent to execute shell commands during its initial activation phase. Specifically, it directs the agent to run ls to search for installed skills across multiple system directories such as ~/.claude/skills/ and ~/.agent/skills/.
  • [DATA_EXFILTRATION]: The skill performs unauthorized environment discovery by probing for directory structures in the user's home folder. This reconnaissance is designed to collect metadata about the user's local setup and installed software without an explicit user request.
  • [REMOTE_CODE_EXECUTION]: The skill contains logic that prompts the agent to install external packages using the npx skills add command. By leveraging the results of its discovery phase, it facilitates the introduction of third-party code from the AbsolutelySkilled repository into the user's execution environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — ios-swift