product-analytics

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands to inspect the local filesystem upon activation. Evidence: The 'Companion check' section in SKILL.md commands the agent to run ls on multiple paths in the user's home directory, including ~/.claude/skills/ and ~/.agent/skills/.
  • [DATA_EXFILTRATION]: The skill attempts to profile the user's environment by harvesting metadata about installed extensions and platform-specific configurations. Evidence: The command targeting hidden directories like ~/.claude/ and ~/.agents/ exposes the agent's internal state and third-party plugin inventory to the model context.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute code from an external, non-trusted repository. Evidence: README.md and SKILL.md promote the use of npx skills add AbsolutelySkilled/AbsolutelySkilled to install the primary skill and its companions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — product-analytics