maestro-update

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute the maestro update command for project migrations and the cp command to create timestamped backups of the workflow state file.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface because it is instructed to load and follow instructions from external markdown files located in ~/.maestro/workflows/updates/. (1) Ingestion points: Local setup documents in the user's home directory. (2) Boundary markers: Absent. (3) Capability inventory: The agent can use Bash, Write, and Edit tools while following instructions from these files. (4) Sanitization: No content validation or sanitization is performed on the loaded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:17 PM
Security Audit — agent-trust-hub — maestro-update