skills-ci
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a prompt factory, generating YAML fix plans that contain instructions for a downstream agent (the
code-runner). These generated instructions incorporate strings from potentially untrusted files found within the scanned skills directory. - Ingestion points: Metadata and code content from files under
.pi/skillsare ingested byantipattern_scanner.pyanddep_scanner.py, then processed into prompts bygenerate_fix_plan.py(line 128). - Boundary markers: Prompts generated in the output YAML files use labels like 'Message:' but do not employ explicit delimiters or 'ignore embedded instructions' warnings for the interpolated violation messages.
- Capability inventory: The secondary agent (
code-runner) possesses high-privilege capabilities including file modification and shell command execution. - Sanitization: No escaping or validation of the interpolated strings was detected in the prompt generation logic.
- [DYNAMIC_EXECUTION]: The script
cache_audit.pyincludes a fix mechanism (line 155) that performs directory deletions usingshutil.rmtreeand environment synchronization usinguv syncon paths discovered during a workspace-widerglobpass. This behavior could be abused if the tool is induced to process a manipulated directory structure, leading to unintended deletions or the synchronization of a malicious dependency environment.
Audit Metadata