assistant-lab

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The run.sh script utilizes python3 -c to run complex Python logic by interpolating shell variables directly into Python code strings. This creates a potential vector for code injection if task names or model types are maliciously crafted.
  • [COMMAND_EXECUTION]: The skill heavily relies on subprocess.run in bridge.py and shell-based orchestration in run.sh to trigger secondary skills and system commands for model lifecycle management.
  • [EXTERNAL_DOWNLOADS]: The workbench orchestrates remote training on RunPod GPUs, involving interaction with external cloud infrastructure, resource provisioning, and weight transfers.
  • [DATA_EXFILTRATION]: The skill reads from and manages sensitive local data stores, including ~/.pi/assistant/shadow.jsonl and model_registry.json, which contain interaction history and model configuration.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present in synthesis_eval.py, where the skill automatically extracts historical user inputs from shadow.jsonl to generate new evaluation prompts for the assistant, potentially re-injecting malicious instructions found in previous logs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — assistant-lab