assistant-lab
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
run.shscript utilizespython3 -cto run complex Python logic by interpolating shell variables directly into Python code strings. This creates a potential vector for code injection if task names or model types are maliciously crafted. - [COMMAND_EXECUTION]: The skill heavily relies on
subprocess.runinbridge.pyand shell-based orchestration inrun.shto trigger secondary skills and system commands for model lifecycle management. - [EXTERNAL_DOWNLOADS]: The workbench orchestrates remote training on RunPod GPUs, involving interaction with external cloud infrastructure, resource provisioning, and weight transfers.
- [DATA_EXFILTRATION]: The skill reads from and manages sensitive local data stores, including
~/.pi/assistant/shadow.jsonlandmodel_registry.json, which contain interaction history and model configuration. - [PROMPT_INJECTION]: An indirect prompt injection surface is present in
synthesis_eval.py, where the skill automatically extracts historical user inputs fromshadow.jsonlto generate new evaluation prompts for the assistant, potentially re-injecting malicious instructions found in previous logs.
Audit Metadata