analytics-engineering
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
SKILL.mdfile contains a 'Companion check' section that instructs the agent to execute a shell command (ls) against several filesystem paths, including~/.claude/skills/and~/.agent/skills/, when the skill is first activated. This probing operation is designed to inventory other installed skills so the agent can recommend additional products from the author. This automated environment discovery occurs without explicit user consent for the filesystem scan and serves a promotional rather than functional purpose.
Audit Metadata