rune-tasks

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is centered around the execution of the 'rune' CLI tool via shell commands. These commands take user-provided strings for file paths, task titles, and details. This could potentially be leveraged for command injection if the agent does not properly escape inputs before passing them to the shell execution environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external markdown files (e.g., 'tasks.md', 'requirements.md') which may contain untrusted data. This content is displayed to the agent through commands like 'rune list' or 'rune next', creating a vector for indirect prompt injection.\n
  • Ingestion points: Content is ingested from user-controlled files via 'rune list', 'rune find', 'rune next', and 'rune streams'.\n
  • Boundary markers: The instructions do not define clear delimiters or warnings to ignore instructions embedded within the task data.\n
  • Capability inventory: The agent can perform subprocess calls (rune) to write to the filesystem and manage task metadata.\n
  • Sanitization: No sanitization or validation of the file contents is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:34 PM