customer-success-playbook

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (ls) to inspect the user's local filesystem for specific directories associated with AI agent skill installations (e.g., ~/.claude/skills/, ~/.agent/skills/). This action is intended to check for companion skills but constitutes unauthorized environment discovery if performed automatically without explicit user request.
  • [PROMPT_INJECTION]: The skill contains behavioral instructions that mandate specific agent actions upon activation, such as always starting responses with a specific emoji and automatically performing filesystem checks and installation prompts for other vendor skills. These instructions could override standard agent protocols or user-defined preferences.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and activation instructions encourage the download and execution of additional remote content from the AbsolutelySkilled GitHub repository using the npx skills add command.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — customer-success-playbook