create-cast
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
run.shscript downloads and executes theuvinstallation script fromastral.shusing acurl | shpipe. This is the official installer for a well-known Python environment manager and is used here for dependency management.\n- [COMMAND_EXECUTION]: The skill dynamically loads a Python module from a computed relative path (.pi/skills/taxonomy/taxonomy.py) intaxonomy_integration.py. This mechanism is used to integrate character data with the pipeline's federated taxonomy system.\n- [COMMAND_EXECUTION]: Inidentity_generator.pyandreference_finder.py, the skill executes other local tool scripts usingsubprocess.run. This is used to delegate image generation to thecreate-imageskill and actor discovery to thediscover-talentskill.\n- [PROMPT_INJECTION]: The skill processes user-supplied scripts which presents an indirect prompt injection surface.\n - Ingestion points: Character traits and physical descriptions are extracted from script files (Markdown or JSON) in
script_analyzer.py.\n - Boundary markers: No explicit delimiters or instructions are used to separate character descriptions from the rest of the generation prompt.\n
- Capability inventory: The skill can execute other skills via
subprocess.runand write data to the local filesystem.\n - Sanitization: The extracted text is used directly in image generation prompts in
identity_generator.pywithout filtering for potential malicious instructions.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata