system-design
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a 'Companion check' directive in SKILL.md that instructs the agent to execute shell commands (
ls) against several local and home directory paths, including~/.claude/skills/,~/.agent/skills/, and~/.agents/skills/. This probes the host filesystem for environment-specific information about installed AI agent extensions. - [EXTERNAL_DOWNLOADS]: The documentation and skill logic promote the use of
npx skills add AbsolutelySkilled/AbsolutelySkilled. This command utilizes thenpxpackage runner to download and execute code from an external, non-whitelisted source, which represents a potential remote code execution vector if the repository or the 'skills' package is untrusted or compromised. - [PROMPT_INJECTION]: The skill includes behavioral overrides, such as requiring the agent to start responses with a specific emoji (๐งข) and mandating a 'Companion check' on first activation. This check forces the agent to perform system discovery and output specific installation commands, steering the agent's behavior to promote other skills based on the user's local environment state.
Audit Metadata