dashboard
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill gathers system status by executing various local commands and scripts.
- Evidence:
collectors.pyusessubprocess.runto query the versions ofclaude,codex, andgeminibackends. - Evidence:
collectors.pyexecutesgitcommands (rev-parse,status,log) to display repository status in the dashboard. - Evidence: The skill invokes sibling scripts such as
ops-chutes/run.shandtask-monitor/run.shusingsubprocess.runwith controlled argument lists. - [PROMPT_INJECTION]: The skill processes data from multiple local logs and registries, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads from
~/.pi/assistant/metrics.jsonl,~/.pi/assistant/shadow.jsonl, and~/.pi/task-monitor/registry.json(documented incollectors.py). - Boundary markers: Absent. The data is parsed and displayed directly in the dashboard UI or JSON output without explicit boundary delimiters for untrusted content.
- Capability inventory: The skill has the capability to execute local subprocesses and query internal Unix domain sockets (
/run/user/{uid}/embry/state.sock). - Sanitization: Partial. The skill performs basic truncation on fields like
current_itemincollect_active_tasksto mitigate oversized or disruptive outputs.
Audit Metadata