product-strategy

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The 'Companion check' section in SKILL.md directs the agent to execute shell commands (ls) targeting specific directories in the user's home folder (e.g., ~/.claude/skills/, ~/.agent/skills/). This allows the agent to perform local environment discovery to identify other installed components.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to recommend and facilitate the installation of additional tools from an external GitHub repository (AbsolutelySkilled/AbsolutelySkilled) using npx. This source is not categorized as a trusted vendor, and promoting the download of external code increases the risk of supply chain attacks or unauthorized software installation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — product-strategy