technical-writing
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform local environment discovery by executing an
lscommand on various potential skill installation paths (e.g.,~/.claude/skills/,~/.agent/skills/). This is used for the 'Companion check' feature to determine which recommended plugins are missing. - [EXTERNAL_DOWNLOADS]: The skill documentation and internal instructions recommend downloading additional code packages from an external repository using the command
npx skills add AbsolutelySkilled/AbsolutelySkilled. While this is an external execution pattern, it is consistent with the skill's role as part of a modular toolset. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to review and process untrusted external documentation provided by the user. It lacks explicit instructions for the agent to use boundary markers or to ignore instructions embedded within the text being analyzed.
- Ingestion points: The agent processes user-provided documentation files (Markdown, API specs, etc.) during review tasks as described in
SKILL.md. - Boundary markers: Absent. The instructions do not define delimiters for user-provided content.
- Capability inventory: The agent has access to filesystem tools (
ls) and package management tools (npx) as demonstrated in the 'Companion check' logic. - Sanitization: Absent. There are no instructions to sanitize or escape content before interpolation.
Audit Metadata