mise-tasks
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive templates and documentation for executing shell commands via mise tasks. This includes operations for database migrations, build pipelines, and CI/CD workflows. While powerful, these are standard developer tools and the instructions emphasize safe patterns such as using
read_fileinstead ofexecto avoid process overhead. - [REMOTE_CODE_EXECUTION]: In
references/advanced.md, the skill documents the experimental mise featureinclude, which allows importing task definitions from remote URLs (e.g.,https://example.com/tasks.toml). This capability allows the execution of remote code if the source is not trusted. - [EXTERNAL_DOWNLOADS]: The skill recommends several third-party developer tools and libraries across different ecosystems, providing instructions to install them via
pip,npm, andbun. This includes tools like Pants for build orchestration and semantic-release for versioning. - [INDIRECT_PROMPT_INJECTION]: The
references/bootstrap-monorepo.mdfile contains a meta-prompt designed to guide an AI agent through an autonomous project scaffolding process. This involves executing a long sequence of commands based on generated content. The documentation includes a constraint instructing the agent that 'The human will not touch any code', which increases autonomy and should be reviewed by users before execution. - [SAFE]: The skill actively promotes security best practices, such as the use of
redact = truefor environment variables and reading secrets from local files rather than hardcoding them or using dangerous shell execution patterns.
Audit Metadata