orchestrate

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates the entire content of a user-provided markdown task file into a system prompt without sanitization. Ingestion points: The task_file content is read in the cmd_run function within run.sh. Boundary markers: The content is wrapped in markdown code blocks in the prompt template, but these can be escaped by the content itself. Capability inventory: The agent has access to powerful tools like Bash, Read, Write, and Edit as defined in SKILL.md. Sanitization: No sanitization or escaping of the task file content is performed before interpolation.
  • [COMMAND_EXECUTION]: The preflight.sh script automatically executes Python scripts found in the task file. It searches for file paths matching the pattern *sanity/*.py and runs them using the python command. An attacker could specify a path to a malicious script in a task file, leading to arbitrary code execution when the preflight check is run.
  • [COMMAND_EXECUTION]: The quality-gate.sh script automatically detects and executes various test runners (make, pytest, npm, cargo, go) based on the presence of project configuration files. This behavior, while intended for verification, can be exploited to execute arbitrary code if the skill is run against a malicious project directory.
  • [COMMAND_EXECUTION]: The skill implements a scheduling system that modifies the scheduler's configuration file (~/.pi/scheduler/jobs.json) to create recurring tasks. This provides a mechanism for persistent command execution on the host system.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — orchestrate