monitor-skills

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes rsync and subprocess.run to synchronize files across projects and execute commands from sibling skills such as scheduler, memory, and agent-inbox. Evidence is found in run.sh and probes/skill_gap.py.
  • [PROMPT_INJECTION]: The gap detection pipeline processes user requests extracted from transcripts and episodic memory, creating a surface for indirect prompt injection when these requests are passed to an LLM-based teacher model.
  • Ingestion points: probes/skill_gap.py extracts user requests from transcripts via mine_unserved_requests and from episodic archives via query_episodic_gaps.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the processing flow for the teacher model.
  • Capability inventory: The skill can write to the local filesystem, perform synchronization across project folders, and trigger executions in other skills.
  • Sanitization: The skill lacks sanitization or validation of the mined request strings before they influence the detection cascade.
  • [REMOTE_CODE_EXECUTION]: The skill performs unsafe deserialization using the pickle module to load a machine learning classifier from the local filesystem. Evidence is found in probes/skill_gap.py within the tier05_gap_classifier function.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — monitor-skills