product-discovery
Fail
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a directive for the agent to execute shell commands to probe the user's system.\n
- The 'Companion check' section in
SKILL.mdinstructs the agent to runlson multiple paths including~/.claude/skills/,~/.agent/skills/, and~/.agents/skills/.\n - This behavior explores hidden application directories to discover other installed extensions without explicit granular consent for file system scanning.\n- [REMOTE_CODE_EXECUTION]: The skill promotes the use of
npxto download and run tools from an unverified third-party repository.\n - The installation instructions in
README.mdandSKILL.mdsuggest runningnpx skills add AbsolutelySkilled/AbsolutelySkilled.\n - Executing code from the 'AbsolutelySkilled' GitHub organization and the 'skills' NPM package introduces arbitrary code execution risks from non-trusted sources.\n- [EXTERNAL_DOWNLOADS]: The skill relies on external components hosted on non-trusted domains.\n
- It directs the agent to suggest downloading and installing additional skills from
absolutelyskilled.proand associated GitHub repositories during runtime.\n- [PROMPT_INJECTION]: The 'Companion check' section inSKILL.mduses directive language to override the agent's default behavior, forcing it to execute discovery commands and installation prompts upon first activation.
Recommendations
- AI detected serious security threats
Audit Metadata