configure-mise
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions advise the agent to provide the user with a command (
curl https://mise.run | sh) to install the mise utility. Although this is the tool's official installation method, piped shell execution from remote URLs is a high-risk pattern. - [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!command`` syntax to execute shell commands likepwdandfindwhen the skill is loaded. These commands are used to identify existing configuration files (e.g.,mise.toml,.tool-versions) and project structure for context gathering. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes various project-controlled configuration files and has the capability to execute shell commands (
Bash) and modify the filesystem. A malicious configuration file or Makefile in a project directory could potentially influence the agent's behavior during migration or audit tasks. - Ingestion points: Reads project configuration files including
mise.toml,Makefile,Brewfile, and legacy version files like.tool-versions. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present for the ingested file content.
- Capability inventory: Uses
Bash,Write,Edit,Read, andGreptools. - Sanitization: No specific sanitization or validation of the ingested file content is mentioned before it is processed or used to influence agent decisions.
Recommendations
- HIGH: Downloads and executes remote code from: https://mise.run - DO NOT USE without thorough review
Audit Metadata