monitor-taxonomy

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to invoke the run.sh scripts of sibling skills including memory, assistant, and create-gpt for database access and model management.
  • [PROMPT_INJECTION]: The skill contains non-negotiable instructions in SKILL.md directing the agent to maintain continuous, autonomous operation and disregard standard status-reporting protocols. It also exhibits an indirect prompt injection surface in cascade_taxonomy.py where document text is interpolated into prompts. (Ingestion: ArangoDB documents; Boundaries: Label markers present, explicit bypass instructions absent; Capabilities: Subprocess execution and file writes; Sanitization: Truncation to 3000 chars).
  • [REMOTE_CODE_EXECUTION]: The tier15_classifier function in cascade_taxonomy.py performs dynamic code loading using importlib.util to execute the infer.py script from the create-gpt skill.
  • [EXTERNAL_DOWNLOADS]: The skill has critical functional dependencies on the presence of sibling skills (memory, assistant, taxonomy, create-gpt, scillm, scheduler) within the local agent environment.
  • [CREDENTIALS_UNSAFE]: The skill persists training labels and metrics to a local state directory (~/.pi/monitor-taxonomy) and uses environment variables for unauthenticated database connections.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — monitor-taxonomy