stelow-product-trust-building

Warn

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references and provides installation instructions for several third-party tools and plugins from unverifiable sources outside the trusted vendor list, including github.com/cursor/plugins, github.com/PriNova/pi-agent-codebase-workflows, and various NPM packages like @earendil-works/pi-agent-browser and @tintinweb/pi-tasks.
  • [COMMAND_EXECUTION]: The 'Execution Loop Protocol' described in execution-loop.md and goals.md outlines a process where the agent reads 'verify commands' from a checkpoint.json file and executes them directly in the shell. Since these commands are derived from project-level specification files (spec-tech.md), this mechanism allows for arbitrary command execution guided by external data.
  • [PROMPT_INJECTION]: The skill acts as an orchestrator that ingests and processes various project artifacts such as spec-product.md, stelow.json, and checklist.md. This creates a surface for indirect prompt injection, where instructions embedded within these files could manipulate the agent's workflow or bypass safety guidelines.
  • [REMOTE_CODE_EXECUTION]: The instructions recommend using npx to execute code from @earendil-works/pi-agent-browser and cursor/plugins, which involves fetching and running code from remote repositories at runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 18, 2026, 10:49 AM
Security Audit — agent-trust-hub — stelow-product-trust-building