analytics
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill employs
importlibandsys.pathmanipulation to dynamically load Python modules from sibling directories (e.g.,create-figureandtaxonomy). This creates a functional dependency on the integrity of code residing in those locations. - [DYNAMIC_EXECUTION]: The skill utilizes
joblib.load()to deserialize machine learning models from the local path~/.pi/models/. Usingjoblibfor deserialization (which relies onpickleinternally) can lead to arbitrary code execution if an attacker manages to place a malicious file at that location. - [COMMAND_EXECUTION]: In
src/cli.py, the skill usessubprocess.runto call an external shell script from a sibling skill (create-figure/run.sh). It passes arguments to this script that may be derived from the data being analyzed. - [EXTERNAL_DOWNLOADS]: The
run.shscript suggests a command to the user for installing theuvtool via a remote shell pipe (curl -LsSf https://astral.sh/uv/install.sh | sh). While this targets a well-known and reputable service (Astral), it documents and encourages a high-risk execution pattern. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted datasets (JSON, JSONL, CSV) and uses the data to generate narrative reports and chart specifications, creating a surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the context through
load_dataandload_jsonlinsrc/insights.py. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The skill has the ability to execute shell commands and load dynamic code.
- Sanitization: The skill does not appear to perform escaping or validation of data values before including them in the generated Horus-style narrative reports.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata