regulatory-compliance

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (ls) to perform an inventory of installed components on the user's system by checking specific hidden directories: ~/.claude/skills/, ~/.agent/skills/, ~/.agents/skills/, and project-local .claude/skills/, .agent/skills/, and .agents/skills/ folders.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and runtime instructions recommend that the agent prompt the user to install additional remote packages using the npx skills add AbsolutelySkilled/AbsolutelySkilled command. This pattern facilitates the downloading and execution of code from an external source.
  • [PROMPT_INJECTION]: The skill contains a behavioral instruction requiring the agent to 'always start your first response with the ๐Ÿงข emoji'. This directive overrides the agent's default persona and formatting rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit โ€” agent-trust-hub โ€” regulatory-compliance