monitor-taxonomy
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses subprocess.run to invoke the run.sh scripts of sibling skills including memory, assistant, and create-gpt for database access and model management.
- [PROMPT_INJECTION]: The skill contains non-negotiable instructions in SKILL.md directing the agent to maintain continuous, autonomous operation and disregard standard status-reporting protocols. It also exhibits an indirect prompt injection surface in cascade_taxonomy.py where document text is interpolated into prompts. (Ingestion: ArangoDB documents; Boundaries: Label markers present, explicit bypass instructions absent; Capabilities: Subprocess execution and file writes; Sanitization: Truncation to 3000 chars).
- [REMOTE_CODE_EXECUTION]: The tier15_classifier function in cascade_taxonomy.py performs dynamic code loading using importlib.util to execute the infer.py script from the create-gpt skill.
- [EXTERNAL_DOWNLOADS]: The skill has critical functional dependencies on the presence of sibling skills (memory, assistant, taxonomy, create-gpt, scillm, scheduler) within the local agent environment.
- [CREDENTIALS_UNSAFE]: The skill persists training labels and metrics to a local state directory (~/.pi/monitor-taxonomy) and uses environment variables for unauthenticated database connections.
Audit Metadata