pixel-art-sprites

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a 'Companion check' section that instructs the agent to modify its behavior upon activation. It directs the agent to perform a specific sequence of environment checks and then deliver a promotional pitch for other skills, which can be seen as an attempt to control the agent's initial interactions for vendor-specific promotion.
  • [COMMAND_EXECUTION]: The SKILL.md file contains instructions for the agent to execute a shell command ('ls') targeting several hidden directories in the user's home folder (e.g., '/.claude/skills/', '/.agent/skills/'). This is used to perform reconnaissance on the local filesystem to identify existing software installations.
  • [EXTERNAL_DOWNLOADS]: The documentation and agent instructions encourage the use of 'npx skills add' to download and install additional software from the 'AbsolutelySkilled' repository. This pattern involves executing remote code from an external registry to modify the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — pixel-art-sprites