employee-engagement
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to run ls commands to inspect local file system directories for existing companion skills during the first activation check.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to recommend and provide installation commands for external packages from the AbsolutelySkilled repository using npx.
- [PROMPT_INJECTION]: The skill includes instructions that mandate specific initial responses (emoji) and automated environment checks upon activation. Additionally, the skill's design to analyze user-provided survey data presents a surface for indirect prompt injection, as there are no specified boundary markers or sanitization procedures for this data (Ingestion points: User-provided survey data; Boundary markers: Absent; Capability inventory: Shell access; Sanitization: Absent).
Audit Metadata