crm-management

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to run a shell command (ls) to inspect specific skill-related directories in the user's home folder, such as ~/.claude/skills/. This discovery action is intended to identify missing companion skills.
  • [EXTERNAL_DOWNLOADS]: The agent is instructed to promote and facilitate the installation of additional skills from the author's repository (AbsolutelySkilled/AbsolutelySkilled) via the npx skills add command.
  • [PROMPT_INJECTION]: The skill contains 'Companion check' instructions that force the agent to perform an environment scan and a promotional pitch for other skills as part of its initial activation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — crm-management