monitor-skills
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
rsyncandsubprocess.runto synchronize files across projects and execute commands from sibling skills such asscheduler,memory, andagent-inbox. Evidence is found inrun.shandprobes/skill_gap.py. - [PROMPT_INJECTION]: The gap detection pipeline processes user requests extracted from transcripts and episodic memory, creating a surface for indirect prompt injection when these requests are passed to an LLM-based teacher model.
- Ingestion points:
probes/skill_gap.pyextracts user requests from transcripts viamine_unserved_requestsand from episodic archives viaquery_episodic_gaps. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the processing flow for the teacher model.
- Capability inventory: The skill can write to the local filesystem, perform synchronization across project folders, and trigger executions in other skills.
- Sanitization: The skill lacks sanitization or validation of the mined request strings before they influence the detection cascade.
- [REMOTE_CODE_EXECUTION]: The skill performs unsafe deserialization using the
picklemodule to load a machine learning classifier from the local filesystem. Evidence is found inprobes/skill_gap.pywithin thetier05_gap_classifierfunction.
Audit Metadata