p9
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/p9.pyutilizessubprocess.runandsubprocess.Popenwithshell=Trueacross several functions, includingcmd_heal,cmd_wait_for, and_deliver_command. This allows the skill to execute shell commands to perform linting, formatting, and other 'healing' tasks. - [DYNAMIC_EXECUTION]: In the
cmd_wait_forfunction, shell commands are dynamically assembled using user-provided presets and target strings. These assembled strings are then executed via the shell without comprehensive sanitization, which could lead to command injection if inputs are maliciously crafted. - [DATA_EXFILTRATION]: The skill is designed to send PR status reports and excerpts from failure logs to external endpoints, such as the well-known service
ntfy.shor user-defined webhooks. This provides a mechanism for notifying users but also facilitates the transmission of project-related data to external servers. - [INDIRECT_PROMPT_INJECTION]: The skill's healing logic ingests data from external CI logs via
gh run view --log-failed. This untrusted data is then processed by a regex-based classifier to trigger automated shell commands, creating a potential vector for indirect influence over the skill's operation through maliciously crafted CI output. - Ingestion points: CI logs are retrieved in
scripts/p9.pyvia_gh_log_failed. - Boundary markers: The skill does not employ explicit boundary markers to delimit untrusted log content.
- Capability inventory: The skill has the capability to execute shell commands and perform network requests.
- Sanitization: The skill uses a regex-based rubric for classification, which provides a level of filtering but does not fully sanitize the input for shell execution.
Audit Metadata