contract-drafting
Fail
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill contains instructions for the agent to execute shell commands (
ls) to inspect multiple hidden configuration directories such as~/.claude/skills/and~/.agent/skills/. This allows the agent to fingerprint the user's environment and identify other installed tools without explicit user authorization.- [EXTERNAL_DOWNLOADS]: The skill directs the agent to offer the installation of additional 'companion skills' from an unverified third-party repository (AbsolutelySkilled/AbsolutelySkilled) using thenpxcommand. Downloading and executing code from an unknown source poses a significant supply chain risk.
Recommendations
- AI detected serious security threats
Audit Metadata