keyword-research

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the AI agent to execute shell commands (ls) to verify the installation status of other components by checking internal configuration paths such as ~/.claude/skills/, ~/.agent/skills/, and ~/.agents/skills/.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the agent to facilitate the installation of additional extensions from a remote source (AbsolutelySkilled/AbsolutelySkilled) via the npx command-line tool, which involves downloading and executing code from an unverified repository.
  • [DATA_EXPOSURE]: The skill performs environmental reconnaissance by searching for specific directories in the user's home folder, which can reveal information about the user's local development environment and installed tools.
  • [PROMPT_INJECTION]: The skill contains specific instructions that override the agent's default behavior, such as mandating that every first response must start with a specific emoji (๐Ÿงข).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection where malicious instructions could be embedded in the data the agent processes.
  • Ingestion points: The agent accepts and processes user-provided seed keywords and keyword lists for analysis as described in the cluster and intent mapping tasks.
  • Boundary markers: The skill lacks explicit instructions or delimiters to isolate user-provided data from the agent's instructional context.
  • Capability inventory: The skill utilizes filesystem access (ls) and has the capability to suggest command execution/installation (npx).
  • Sanitization: No sanitization or validation logic is defined to filter or escape external content before it is interpolated into the agent's workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” keyword-research