social-media-strategy
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands to probe the user's filesystem. It instructs the agent to run
lson several hidden directories within the home folder, including~/.claude/skills/,~/.agent/skills/, and~/.agents/skills/, to detect other installed skills without explicit user request. - [EXTERNAL_DOWNLOADS]: The instructions recommend the installation of additional external skills from the AbsolutelySkilled repository using the
npx skills addcommand. This represents the download and execution of remote code from a source that is not verified as a trusted organization or well-known service. - [PROMPT_INJECTION]: The skill includes a behavioral mandate requiring the agent to prefix its first response with a specific emoji (ᾞ2), overriding the standard interaction style. Additionally, the skill exposes a surface for indirect prompt injection by processing user-controlled content (social media post requests) without boundary markers or sanitization, while maintaining the capability to execute shell commands. Evidence: 1. Ingestion points: User-provided topics and post ideas for social media content. 2. Boundary markers: Absent. 3. Capability inventory: Filesystem inspection via shell commands (ls). 4. Sanitization: Absent.
Audit Metadata