muse-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides an installation command that downloads and executes a shell script from https://dev.meta.ai/install.sh. This is an official installation method from a well-known service (Meta).
  • [EXTERNAL_DOWNLOADS]: Fetches the Muse CLI tool and documentation from Meta's dev.meta.ai domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a delegation layer that passes repository context and user prompts to the muse CLI tool, creating an attack surface for indirect injection if project files contain malicious instructions.
  • Ingestion points: Local repository files and user-provided prompts processed by the muse exec command as described in SKILL.md.
  • Boundary markers: None explicitly defined in the prompt construction instructions.
  • Capability inventory: Execution of shell commands via the muse binary and script execution through delegation_executor.py.
  • Sanitization: Not specified; the skill relies on the underlying tool's handling of input strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — muse-delegation