mise-guide
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to install the
miseutility by downloading a script from an external URL and piping it directly to the system shell. This pattern is inherently risky as it executes remote code without verification. - Evidence:
SKILL.mdcontains the installation instructioncurl https://mise.run | sh. - [INDIRECT_PROMPT_INJECTION]: The skill supports the creation of project tasks that interpolate user-provided arguments directly into shell commands, creating a surface for indirect prompt injection or command injection attacks.
- Ingestion points: User-supplied parameters for tasks defined in
references/tasks.mdand executed viaSKILL.md. - Boundary markers: The skill does not provide instructions for using delimiters or warnings to ignore embedded instructions when processing user-supplied arguments.
- Capability inventory: The agent is authorized to run shell commands (
mise run) and modify project configuration files (mise.toml) as described inSKILL.mdandreferences/tools.md. - Sanitization: There are no instructions provided to sanitize, escape, or validate user-supplied arguments before they are executed in the shell.
- [DYNAMIC_EXECUTION]: The
misetask runner functionality allows for the definition and execution of arbitrary shell commands from configuration files, including those with dynamic argument interpolation ({{arg(...)}}). This represents a risk where the execution flow can be dynamically altered by file content or user input. - Evidence:
references/tasks.mddetails the task runner configuration and argument system. - [EXTERNAL_DOWNLOADS]: The skill instructions and reference materials point to downloading development tools and utilities from various third-party sources, including GitHub releases.
- Evidence:
references/tools.mdincludes examples of installing tools from external repositories, such asmise use "github:BurntSushi/ripgrep".
Recommendations
- HIGH: Downloads and executes remote code from: https://mise.run - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata