tax-strategy
Warn
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
ls) to inspect several filesystem paths, including hidden directories in the user's home folder (e.g.,~/.claude/skills/). This environment discovery is performed automatically upon activation to profile installed plugins. - [EXTERNAL_DOWNLOADS]: The skill recommends installing further components from an untrusted source (
AbsolutelySkilled/AbsolutelySkilled) using thenpxcommand. This promotes fetching and executing remote code from an unverified repository, introducing a supply-chain risk. - [DATA_EXFILTRATION]: The discovery of installed skills and their configurations allows for profiling the agent's environment and the user's setup. This information exposure, focusing on the presence of specific tools, constitutes reconnaissance that could be used for targeted exploitation.
Audit Metadata