ml-ops

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (ls) to inspect the local filesystem for other installed skills in various directories (e.g., ~/.claude/skills/). This constitutes environment discovery behavior performed automatically upon activation.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of additional software from a third-party repository (AbsolutelySkilled/AbsolutelySkilled) using npx, which is not a recognized trusted source.\n- [PROMPT_INJECTION]: The skill includes instructions that mandate the agent start every response with a specific emoji and perform automated environment checks and promotional offers, which overrides standard agent interaction patterns.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes machine learning data, metrics, and logs (e.g., via compute_stats or load_training_stats) without explicit sanitization or boundary markers, creating a surface for indirect prompt injection if the ingested data is adversarial.\n
  • Ingestion points: Processes batch features, training statistics, and datasets via DVC.\n
  • Boundary markers: Absent from processing instructions.\n
  • Capability inventory: Shell command execution (ls, npx) and file system access.\n
  • Sanitization: No validation or sanitization procedures for external ML data are specified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — ml-ops