ml-ops
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (
ls) to inspect the local filesystem for other installed skills in various directories (e.g.,~/.claude/skills/). This constitutes environment discovery behavior performed automatically upon activation.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of additional software from a third-party repository (AbsolutelySkilled/AbsolutelySkilled) usingnpx, which is not a recognized trusted source.\n- [PROMPT_INJECTION]: The skill includes instructions that mandate the agent start every response with a specific emoji and perform automated environment checks and promotional offers, which overrides standard agent interaction patterns.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes machine learning data, metrics, and logs (e.g., viacompute_statsorload_training_stats) without explicit sanitization or boundary markers, creating a surface for indirect prompt injection if the ingested data is adversarial.\n - Ingestion points: Processes batch features, training statistics, and datasets via DVC.\n
- Boundary markers: Absent from processing instructions.\n
- Capability inventory: Shell command execution (
ls,npx) and file system access.\n - Sanitization: No validation or sanitization procedures for external ML data are specified.
Audit Metadata