mise-environment-management

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents the use of the exec template function within mise.toml files (e.g., {{ exec(command='git branch --show-current') }}). This feature allows arbitrary shell commands to be executed when the environment is loaded or variables are resolved.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external configuration files such as mise.toml, .env, and .env.local. If an attacker can influence these files within a project repository, they could potentially trigger malicious actions when the agent interacts with the Mise environment.
  • Ingestion points: mise.toml, .env, .env.local, and global config files.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: The skill utilizes Bash, Write, Edit, and Read tools, which could be leveraged to execute commands or modify system files based on config input.
  • Sanitization: No explicit sanitization or validation of the content within the configuration files is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:22 PM
Security Audit — agent-trust-hub — mise-environment-management