skills-ci

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a prompt factory, generating YAML fix plans that contain instructions for a downstream agent (the code-runner). These generated instructions incorporate strings from potentially untrusted files found within the scanned skills directory.
  • Ingestion points: Metadata and code content from files under .pi/skills are ingested by antipattern_scanner.py and dep_scanner.py, then processed into prompts by generate_fix_plan.py (line 128).
  • Boundary markers: Prompts generated in the output YAML files use labels like 'Message:' but do not employ explicit delimiters or 'ignore embedded instructions' warnings for the interpolated violation messages.
  • Capability inventory: The secondary agent (code-runner) possesses high-privilege capabilities including file modification and shell command execution.
  • Sanitization: No escaping or validation of the interpolated strings was detected in the prompt generation logic.
  • [DYNAMIC_EXECUTION]: The script cache_audit.py includes a fix mechanism (line 155) that performs directory deletions using shutil.rmtree and environment synchronization using uv sync on paths discovered during a workspace-wide rglob pass. This behavior could be abused if the tool is induced to process a manipulated directory structure, leading to unintended deletions or the synchronization of a malicious dependency environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — skills-ci