maestro-update
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute the maestro update command for project migrations and the cp command to create timestamped backups of the workflow state file.
- [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface because it is instructed to load and follow instructions from external markdown files located in ~/.maestro/workflows/updates/. (1) Ingestion points: Local setup documents in the user's home directory. (2) Boundary markers: Absent. (3) Capability inventory: The agent can use Bash, Write, and Edit tools while following instructions from these files. (4) Sanitization: No content validation or sanitization is performed on the loaded instructions.
Audit Metadata