create-cast

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The run.sh script downloads and executes the uv installation script from astral.sh using a curl | sh pipe. This is the official installer for a well-known Python environment manager and is used here for dependency management.\n- [COMMAND_EXECUTION]: The skill dynamically loads a Python module from a computed relative path (.pi/skills/taxonomy/taxonomy.py) in taxonomy_integration.py. This mechanism is used to integrate character data with the pipeline's federated taxonomy system.\n- [COMMAND_EXECUTION]: In identity_generator.py and reference_finder.py, the skill executes other local tool scripts using subprocess.run. This is used to delegate image generation to the create-image skill and actor discovery to the discover-talent skill.\n- [PROMPT_INJECTION]: The skill processes user-supplied scripts which presents an indirect prompt injection surface.\n
  • Ingestion points: Character traits and physical descriptions are extracted from script files (Markdown or JSON) in script_analyzer.py.\n
  • Boundary markers: No explicit delimiters or instructions are used to separate character descriptions from the rest of the generation prompt.\n
  • Capability inventory: The skill can execute other skills via subprocess.run and write data to the local filesystem.\n
  • Sanitization: The extracted text is used directly in image generation prompts in identity_generator.py without filtering for potential malicious instructions.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — create-cast