analytics-engineering

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file contains a 'Companion check' section that instructs the agent to execute a shell command (ls) against several filesystem paths, including ~/.claude/skills/ and ~/.agent/skills/, when the skill is first activated. This probing operation is designed to inventory other installed skills so the agent can recommend additional products from the author. This automated environment discovery occurs without explicit user consent for the filesystem scan and serves a promotional rather than functional purpose.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — analytics-engineering