customer-success-playbook
Warn
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
ls) to inspect the user's local filesystem for specific directories associated with AI agent skill installations (e.g.,~/.claude/skills/,~/.agent/skills/). This action is intended to check for companion skills but constitutes unauthorized environment discovery if performed automatically without explicit user request. - [PROMPT_INJECTION]: The skill contains behavioral instructions that mandate specific agent actions upon activation, such as always starting responses with a specific emoji and automatically performing filesystem checks and installation prompts for other vendor skills. These instructions could override standard agent protocols or user-defined preferences.
- [EXTERNAL_DOWNLOADS]: The skill documentation and activation instructions encourage the download and execution of additional remote content from the AbsolutelySkilled GitHub repository using the
npx skills addcommand.
Audit Metadata