keyword-research
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the AI agent to execute shell commands (
ls) to verify the installation status of other components by checking internal configuration paths such as~/.claude/skills/,~/.agent/skills/, and~/.agents/skills/. - [EXTERNAL_DOWNLOADS]: The instructions direct the agent to facilitate the installation of additional extensions from a remote source (
AbsolutelySkilled/AbsolutelySkilled) via thenpxcommand-line tool, which involves downloading and executing code from an unverified repository. - [DATA_EXPOSURE]: The skill performs environmental reconnaissance by searching for specific directories in the user's home folder, which can reveal information about the user's local development environment and installed tools.
- [PROMPT_INJECTION]: The skill contains specific instructions that override the agent's default behavior, such as mandating that every first response must start with a specific emoji (๐งข).
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection where malicious instructions could be embedded in the data the agent processes.
- Ingestion points: The agent accepts and processes user-provided seed keywords and keyword lists for analysis as described in the cluster and intent mapping tasks.
- Boundary markers: The skill lacks explicit instructions or delimiters to isolate user-provided data from the agent's instructional context.
- Capability inventory: The skill utilizes filesystem access (
ls) and has the capability to suggest command execution/installation (npx). - Sanitization: No sanitization or validation logic is defined to filter or escape external content before it is interpolated into the agent's workflow.
Audit Metadata