quality-audit

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The run.sh script suggests a command to download and install the uv package manager from https://astral.sh/uv/install.sh. This is the official distribution domain for a well-known developer tool.
  • [PROMPT_INJECTION]: The quality_audit.py script generates prompts for 'UltraThink mode' by interpolating untrusted data from input files, creating a surface for indirect prompt injection.
  • Ingestion points: Data is ingested from user-specified JSON or JSONL files via the load_input function in quality_audit.py.
  • Boundary markers: The generated prompt uses Markdown headers and code blocks to separate fields but does not include explicit instructions to the LLM to ignore nested commands within the data.
  • Capability inventory: The skill leverages the Bash, Read, and Write tools to perform operations and generate reports.
  • Sanitization: There is no evidence of sanitization or escaping of input fields before they are embedded into the prompt template.
  • [COMMAND_EXECUTION]: The memory_integration.py file dynamically loads a taxonomy module using importlib.util.spec_from_file_location, and quality_audit.py modifies the Python search path to import internal utilities from the .pi/skills directory.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — quality-audit