configure-mise

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions advise the agent to provide the user with a command (curl https://mise.run | sh) to install the mise utility. Although this is the tool's official installation method, piped shell execution from remote URLs is a high-risk pattern.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the !command`` syntax to execute shell commands like pwd and find when the skill is loaded. These commands are used to identify existing configuration files (e.g., mise.toml, .tool-versions) and project structure for context gathering.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes various project-controlled configuration files and has the capability to execute shell commands (Bash) and modify the filesystem. A malicious configuration file or Makefile in a project directory could potentially influence the agent's behavior during migration or audit tasks.
  • Ingestion points: Reads project configuration files including mise.toml, Makefile, Brewfile, and legacy version files like .tool-versions.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present for the ingested file content.
  • Capability inventory: Uses Bash, Write, Edit, Read, and Grep tools.
  • Sanitization: No specific sanitization or validation of the ingested file content is mentioned before it is processed or used to influence agent decisions.
Recommendations
  • HIGH: Downloads and executes remote code from: https://mise.run - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 04:18 PM