orchestrate
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates the entire content of a user-provided markdown task file into a system prompt without sanitization. Ingestion points: The
task_filecontent is read in thecmd_runfunction withinrun.sh. Boundary markers: The content is wrapped in markdown code blocks in the prompt template, but these can be escaped by the content itself. Capability inventory: The agent has access to powerful tools like Bash, Read, Write, and Edit as defined inSKILL.md. Sanitization: No sanitization or escaping of the task file content is performed before interpolation. - [COMMAND_EXECUTION]: The
preflight.shscript automatically executes Python scripts found in the task file. It searches for file paths matching the pattern*sanity/*.pyand runs them using thepythoncommand. An attacker could specify a path to a malicious script in a task file, leading to arbitrary code execution when the preflight check is run. - [COMMAND_EXECUTION]: The
quality-gate.shscript automatically detects and executes various test runners (make, pytest, npm, cargo, go) based on the presence of project configuration files. This behavior, while intended for verification, can be exploited to execute arbitrary code if the skill is run against a malicious project directory. - [COMMAND_EXECUTION]: The skill implements a scheduling system that modifies the scheduler's configuration file (
~/.pi/scheduler/jobs.json) to create recurring tasks. This provides a mechanism for persistent command execution on the host system.
Audit Metadata