dashboard

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill gathers system status by executing various local commands and scripts.
  • Evidence: collectors.py uses subprocess.run to query the versions of claude, codex, and gemini backends.
  • Evidence: collectors.py executes git commands (rev-parse, status, log) to display repository status in the dashboard.
  • Evidence: The skill invokes sibling scripts such as ops-chutes/run.sh and task-monitor/run.sh using subprocess.run with controlled argument lists.
  • [PROMPT_INJECTION]: The skill processes data from multiple local logs and registries, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads from ~/.pi/assistant/metrics.jsonl, ~/.pi/assistant/shadow.jsonl, and ~/.pi/task-monitor/registry.json (documented in collectors.py).
  • Boundary markers: Absent. The data is parsed and displayed directly in the dashboard UI or JSON output without explicit boundary delimiters for untrusted content.
  • Capability inventory: The skill has the capability to execute local subprocesses and query internal Unix domain sockets (/run/user/{uid}/embry/state.sock).
  • Sanitization: Partial. The skill performs basic truncation on fields like current_item in collect_active_tasks to mitigate oversized or disruptive outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — dashboard