load-testing
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a direct instruction for the agent to execute shell commands (
ls) to inspect multiple local directories, including hidden paths in the user's home directory (~/.claude/skills/,~/.agent/skills/, etc.), to check for companion skills. - [DATA_EXFILTRATION]: By instructing the agent to probe local filesystem paths and return the results to its context, the skill exposes environment metadata and information about the user's installed tools.
- [PROMPT_INJECTION]: The skill contains a behavioral directive requiring the agent to "always start your first response with the ๐งข emoji," which overrides the agent's natural output format.
- [EXTERNAL_DOWNLOADS]: The skill documentation promotes the installation of additional components from an unverified source (
AbsolutelySkilled/AbsolutelySkilled) using a custom installer (npx skills add). - [COMMAND_EXECUTION]: Documentation for CI/CD integration provides commands for installing software using elevated privileges (
sudo apt-get install) and adding external repository keys.
Audit Metadata