create-context

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automatically searches for and executes files named 'sanity.sh' located in subdirectories of '.pi/skills/'. This enables the execution of arbitrary scripts from potentially untrusted or third-party skill folders with the permissions of the current user.
  • Evidence (detectors.py): The detect_test_coverage function iterates through directories and calls run_command([str(sanity_sh)], timeout=10) if the file exists.
  • [DATA_EXFILTRATION]: The skill gathers and records sensitive system information into the generated 'CONTEXT.md' file, including environment variables (e.g., storage paths, model configurations) and full paths to session transcripts. While API keys are masked, the exposure of internal directory structures and session data poses a privacy and reconnaissance risk.
  • Evidence (detectors.py): The detect_environment_snapshot and detect_session_transcript functions extract environment state and absolute file paths to conversation histories.
  • [PROMPT_INJECTION]: The tool ingests untrusted data from git commit messages, project documentation ('CLAUDE.md'), and memory files, interpolating this content directly into the handoff document without sanitization or boundary markers. This creates a surface for indirect prompt injection where malicious instructions hidden in project metadata could manipulate the behavior of agents reading the 'CONTEXT.md' file in future sessions.
  • Ingestion points: detectors.py (git logs, project documentation, memory files).
  • Boundary markers: Absent; data is placed directly into markdown sections.
  • Capability inventory: File read/write, environment variable access, and subprocess execution.
  • Sanitization: None detected; content is used verbatim.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — create-context