mise-configuration
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill contains a 'Self-Evolving Skill' directive in
SKILL.mdthat instructs the AI to 'fix this file immediately' if instructions are found to be incorrect or workarounds are needed. This self-referential instruction creates a mechanism for the agent to modify its own logic based on external inputs or runtime experiences, which could be exploited to persist malicious changes. - [DYNAMIC_EXECUTION]: The documentation in
references/patterns.mdpromotes the use of the Tera template engine'sexecfunction within.mise.tomlfiles. This allows for the execution of arbitrary shell commands (e.g.,exec(command='date +%Y-%m-%d')orexec(command='op read ...')) whenever the environment is resolved, creating a surface for dynamic command execution from configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill supports ingesting untrusted data through the
read_filetemplate function and.envfile loading (_.file). - Ingestion points:
read_filefunction and_.filedirectives in.mise.toml(mentioned inreferences/patterns.md). - Boundary markers: Uses Tera delimiters
{{ }}which separate logic from data but do not protect against injection in the content of the files being read. - Capability inventory: Access to
execfor command execution andWrite/Edittools for file modification. - Sanitization: No explicit sanitization or validation rules are provided for data read from external files before it is processed by the template engine.
Audit Metadata