cali-product-execution-critique

Warn

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The main skill logic in SKILL.md uses node -e to execute inline JavaScript for modifying the stelow.json file and python3 -c to process JSON data from the sem tool.
  • [EXTERNAL_DOWNLOADS]: The skill encourages the installation of various extensions from third-party GitHub users, including PriNova/pi-agent-codebase-workflows, nicobailon/pi-intercom, and tintinweb/pi-supervisor.
  • [REMOTE_CODE_EXECUTION]: The codequality-review.md file provides commands to download and execute code from a GitHub repository using pi install git:github.com/cursor/plugins.
  • [COMMAND_EXECUTION]: The skill performs environment discovery by probing the user's home directory for hidden configuration folders such as ~/.pi/, ~/.opencode/, ~/.claude/, and ~/.codex/ to detect the running agent harness.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8).
  • Ingestion points: The skill reads external technical plans (spec-tech*.md), product specifications (spec-product*.md), and live website content via the agent_browser tool.
  • Boundary markers: None identified in the prompt templates or file-reading logic.
  • Capability inventory: The skill possesses high-privilege capabilities including shell access (bash), file system writes (write), and dynamic script execution (node, python).
  • Sanitization: There is no evidence of sanitization or safety delimiters for data ingested from the implementation files or browser snapshots before they are processed by the LLM.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 12:54 PM
Security Audit — agent-trust-hub — cali-product-execution-critique