brand-strategy

Fail

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (ls) targeting sensitive hidden directories in the user's home folder (e.g., ~/.claude/skills/, ~/.agent/skills/). This behavior is used to inventory existing software on the host machine without explicit user initiation.
  • [EXTERNAL_DOWNLOADS]: The skill includes logic to recommend and provide installation commands for additional external skills from an unverified repository (AbsolutelySkilled/AbsolutelySkilled) via npx, which could lead to the introduction of further unvetted code into the environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — brand-strategy