lite
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied goals, scope, and task descriptions, which are later interpolated into prompts for the
pitool. In Phase 3, the output of the task execution model (result_<step>.md) is directly concatenated into the verification prompt (pi -p "Verify: {criteria}\nResult: $(cat result_<step>.md)"). This creates a vulnerability where a malicious or subverted task result could influence the verification process or the behavior of the secondary model. - Ingestion points: User input for goals, scope, and steps collected in Phase 1 and written to files in
/tmp/ralph/. - Boundary markers: No explicit delimiters or instructions are used to separate user-provided data from system instructions in the
picommand prompts. - Capability inventory: Subprocess execution via the
pitool, file read/write operations in the/tmpdirectory, and model invocation. - Sanitization: No validation or escaping is performed on the content of the task briefs or the results before they are passed to the next model invocation.
- [COMMAND_EXECUTION]: The skill uses shell-based command substitution (
$(cat ...)) to pass file contents as arguments to thepitool. If the underlying execution environment does not properly escape these substitutions, malicious content in the temporary files could potentially lead to command injection, although the usage here appears intended for task dispatch. - [DATA_EXPOSURE]: The skill uses the shared
/tmp/directory to store goal, scope, and task information. In multi-user environments, this could lead to data exposure if permissions are not strictly managed by the underlying operating system.
Audit Metadata