mise-environment-management
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents the use of the
exectemplate function withinmise.tomlfiles (e.g.,{{ exec(command='git branch --show-current') }}). This feature allows arbitrary shell commands to be executed when the environment is loaded or variables are resolved. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external configuration files such as
mise.toml,.env, and.env.local. If an attacker can influence these files within a project repository, they could potentially trigger malicious actions when the agent interacts with the Mise environment. - Ingestion points:
mise.toml,.env,.env.local, and global config files. - Boundary markers: None specified in the instructions.
- Capability inventory: The skill utilizes
Bash,Write,Edit, andReadtools, which could be leveraged to execute commands or modify system files based on config input. - Sanitization: No explicit sanitization or validation of the content within the configuration files is mentioned.
Audit Metadata