recommend-skill-chain
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute scripts from peer skills such asmemory/run.shandskill-lab/scripts/chain_miner.py. While these calls use argument lists to prevent shell injection, they represent a dependency on the integrity of external scripts. - [REMOTE_CODE_EXECUTION]: The core logic dynamically modifies the Python
sys.pathto import modules from computed sibling directories (skill-lab,assistant,common) and usesjoblib.loadto deserialize local classifier models from~/.pi/models/. These patterns are consistent with the skill's purpose but represent dynamic code loading and unsafe deserialization surfaces. - [DATA_EXFILTRATION]: The skill accesses and reads from the user's home directory (
~/.pi/assistant/shadow.jsonl) and local skill data directories to aggregate logs and training data, exposing internal state and configurations. - [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill ingests untrusted task descriptions and passes them to multiple downstream components.
- Ingestion points: The
taskparameter inrecommender.recommend()and_tier05_classifier(). - Boundary markers: No explicit delimiters or instructions are used to isolate user input when delegating to other skills.
- Capability inventory: The skill possesses the ability to execute subprocesses and dynamically load modules based on its logic.
- Sanitization: No sanitization or validation of the input task string is performed before it is used in logic or passed to sub-components.
Audit Metadata