pi-cli-runtime
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill constructs a shell command by interpolating user-provided text into a template:
node "${CLAUDE_PLUGIN_ROOT}/scripts/pi-companion.mjs" task "<raw arguments>". This pattern of inserting potentially unescaped strings into a shell context creates a command injection surface. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and forwards it to an external process without comprehensive sanitization or boundary isolation.
- Ingestion points: User-provided task text is received and processed by the
pi:pi-rescuesubagent instructions inSKILL.md. - Boundary markers: No delimiters or shell-escaping instructions are present to ensure user input is treated strictly as data within the command interpolation.
- Capability inventory: The skill is designed specifically to execute shell commands via a
nodescript helper. - Sanitization: The instructions only detail stripping specific functional flags (like
--resumeor--background) but do not include general sanitization for shell metacharacters or command-breaking sequences.
Audit Metadata