mise-configuration

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a 'Self-Evolving Skill' directive in SKILL.md that instructs the AI to 'fix this file immediately' if instructions are found to be incorrect or workarounds are needed. This self-referential instruction creates a mechanism for the agent to modify its own logic based on external inputs or runtime experiences, which could be exploited to persist malicious changes.
  • [DYNAMIC_EXECUTION]: The documentation in references/patterns.md promotes the use of the Tera template engine's exec function within .mise.toml files. This allows for the execution of arbitrary shell commands (e.g., exec(command='date +%Y-%m-%d') or exec(command='op read ...')) whenever the environment is resolved, creating a surface for dynamic command execution from configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill supports ingesting untrusted data through the read_file template function and .env file loading (_.file).
  • Ingestion points: read_file function and _.file directives in .mise.toml (mentioned in references/patterns.md).
  • Boundary markers: Uses Tera delimiters {{ }} which separate logic from data but do not protect against injection in the content of the files being read.
  • Capability inventory: Access to exec for command execution and Write/Edit tools for file modification.
  • Sanitization: No explicit sanitization or validation rules are provided for data read from external files before it is processed by the template engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:23 AM
Security Audit — agent-trust-hub — mise-configuration