recommend-skill-chain

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute scripts from peer skills such as memory/run.sh and skill-lab/scripts/chain_miner.py. While these calls use argument lists to prevent shell injection, they represent a dependency on the integrity of external scripts.
  • [REMOTE_CODE_EXECUTION]: The core logic dynamically modifies the Python sys.path to import modules from computed sibling directories (skill-lab, assistant, common) and uses joblib.load to deserialize local classifier models from ~/.pi/models/. These patterns are consistent with the skill's purpose but represent dynamic code loading and unsafe deserialization surfaces.
  • [DATA_EXFILTRATION]: The skill accesses and reads from the user's home directory (~/.pi/assistant/shadow.jsonl) and local skill data directories to aggregate logs and training data, exposing internal state and configurations.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill ingests untrusted task descriptions and passes them to multiple downstream components.
  • Ingestion points: The task parameter in recommender.recommend() and _tier05_classifier().
  • Boundary markers: No explicit delimiters or instructions are used to isolate user input when delegating to other skills.
  • Capability inventory: The skill possesses the ability to execute subprocesses and dynamically load modules based on its logic.
  • Sanitization: No sanitization or validation of the input task string is performed before it is used in logic or passed to sub-components.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — recommend-skill-chain