skills/a-canary/arc-skills/lite/Gen Agent Trust Hub

lite

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied goals, scope, and task descriptions, which are later interpolated into prompts for the pi tool. In Phase 3, the output of the task execution model (result_<step>.md) is directly concatenated into the verification prompt (pi -p "Verify: {criteria}\nResult: $(cat result_<step>.md)"). This creates a vulnerability where a malicious or subverted task result could influence the verification process or the behavior of the secondary model.
  • Ingestion points: User input for goals, scope, and steps collected in Phase 1 and written to files in /tmp/ralph/.
  • Boundary markers: No explicit delimiters or instructions are used to separate user-provided data from system instructions in the pi command prompts.
  • Capability inventory: Subprocess execution via the pi tool, file read/write operations in the /tmp directory, and model invocation.
  • Sanitization: No validation or escaping is performed on the content of the task briefs or the results before they are passed to the next model invocation.
  • [COMMAND_EXECUTION]: The skill uses shell-based command substitution ($(cat ...)) to pass file contents as arguments to the pi tool. If the underlying execution environment does not properly escape these substitutions, malicious content in the temporary files could potentially lead to command injection, although the usage here appears intended for task dispatch.
  • [DATA_EXPOSURE]: The skill uses the shared /tmp/ directory to store goal, scope, and task information. In multi-user environments, this could lead to data exposure if permissions are not strictly managed by the underlying operating system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:47 PM
Security Audit — agent-trust-hub — lite