product-analytics
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands to inspect the local filesystem upon activation. Evidence: The 'Companion check' section in SKILL.md commands the agent to run
lson multiple paths in the user's home directory, including~/.claude/skills/and~/.agent/skills/. - [DATA_EXFILTRATION]: The skill attempts to profile the user's environment by harvesting metadata about installed extensions and platform-specific configurations. Evidence: The command targeting hidden directories like
~/.claude/and~/.agents/exposes the agent's internal state and third-party plugin inventory to the model context. - [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute code from an external, non-trusted repository. Evidence: README.md and SKILL.md promote the use of
npx skills add AbsolutelySkilled/AbsolutelySkilledto install the primary skill and its companions.
Audit Metadata