skills/saliagadotcom/skills/pi-mom/Gen Agent Trust Hub

pi-mom

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The system is vulnerable to indirect prompt injection attacks because it ingests untrusted data that can influence the agent's behavior.\n
  • Ingestion points: Processes messages from Slack channels, direct messages, and external files via the read tool (SKILL.md, reference/setup.md).\n
  • Boundary markers: No explicit delimiters or instructions are documented to separate untrusted data from the system prompt.\n
  • Capability inventory: High-privilege tools include bash for shell execution, write and edit for filesystem modification, and attach for sharing files (SKILL.md).\n
  • Sanitization: Lacks documented sanitization or filtering of external content.\n- [COMMAND_EXECUTION]: The skill provides a bash tool for arbitrary shell command execution as a core feature.\n
  • This allows the agent to execute any command within its environment, which can lead to host compromise if run without the recommended Docker sandbox.\n- [EXTERNAL_DOWNLOADS]: The documentation references external repositories and packages for installation and extension.\n
  • Encourages installation of the @mariozechner/pi-mom package from NPM and suggests fetching additional skills from the github.com/badlogic/pi-skills repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 02:31 PM
Security Audit — agent-trust-hub — pi-mom