technical-writing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment discovery by executing an ls command on various potential skill installation paths (e.g., ~/.claude/skills/, ~/.agent/skills/). This is used for the 'Companion check' feature to determine which recommended plugins are missing.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and internal instructions recommend downloading additional code packages from an external repository using the command npx skills add AbsolutelySkilled/AbsolutelySkilled. While this is an external execution pattern, it is consistent with the skill's role as part of a modular toolset.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to review and process untrusted external documentation provided by the user. It lacks explicit instructions for the agent to use boundary markers or to ignore instructions embedded within the text being analyzed.
  • Ingestion points: The agent processes user-provided documentation files (Markdown, API specs, etc.) during review tasks as described in SKILL.md.
  • Boundary markers: Absent. The instructions do not define delimiters for user-provided content.
  • Capability inventory: The agent has access to filesystem tools (ls) and package management tools (npx) as demonstrated in the 'Companion check' logic.
  • Sanitization: Absent. There are no instructions to sanitize or escape content before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — technical-writing