cali-product-health
Warn
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The reference file
references/cli-tools/codequality-review.mdprovides instructions to install thecursor/pluginspackage from a third-party GitHub repository (github.com/cursor/plugins). - [EXTERNAL_DOWNLOADS]: The reference file
references/cli-tools/safe-change.mdprovides instructions to install thepi-agent-codebase-workflowspackage from a third-party GitHub repository (github.com/PriNova/pi-agent-codebase-workflows). - [EXTERNAL_DOWNLOADS]: The reference file
references/cli-tools/todo.mdprovides instructions to install the@juicesharp/rpiv-todopackage from the NPM registry. - [EXTERNAL_DOWNLOADS]: The reference file
references/cli-tools/plannotator.mdreferences multiple unverified external packages, including@plannotator/pi-extension,@plannotator/opencode, and@backnotprop/plannotator. - [REMOTE_CODE_EXECUTION]: Multiple reference files within the skill, such as
codequality-review.md,safe-change.md, andtodo.md, provide specific shell commands (e.g.,pi installandnpx skills add) that instruct the agent to download and install executable code from unverified third-party sources, posing a supply chain and remote execution risk.
Audit Metadata