analytics

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs importlib and sys.path manipulation to dynamically load Python modules from sibling directories (e.g., create-figure and taxonomy). This creates a functional dependency on the integrity of code residing in those locations.
  • [DYNAMIC_EXECUTION]: The skill utilizes joblib.load() to deserialize machine learning models from the local path ~/.pi/models/. Using joblib for deserialization (which relies on pickle internally) can lead to arbitrary code execution if an attacker manages to place a malicious file at that location.
  • [COMMAND_EXECUTION]: In src/cli.py, the skill uses subprocess.run to call an external shell script from a sibling skill (create-figure/run.sh). It passes arguments to this script that may be derived from the data being analyzed.
  • [EXTERNAL_DOWNLOADS]: The run.sh script suggests a command to the user for installing the uv tool via a remote shell pipe (curl -LsSf https://astral.sh/uv/install.sh | sh). While this targets a well-known and reputable service (Astral), it documents and encourages a high-risk execution pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted datasets (JSON, JSONL, CSV) and uses the data to generate narrative reports and chart specifications, creating a surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the context through load_data and load_jsonl in src/insights.py.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed data.
  • Capability inventory: The skill has the ability to execute shell commands and load dynamic code.
  • Sanitization: The skill does not appear to perform escaping or validation of data values before including them in the generated Horus-style narrative reports.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — analytics