plankton-code-quality

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a suite of environment hooks (PreToolUse, PostToolUse, and Stop) to execute local shell scripts such as multi_linter.sh and protect_linter_configs.sh whenever file modifications occur.
  • [DYNAMIC_EXECUTION]: Implements a three-phase architecture that spawns claude -p subprocesses to automatically generate and apply code fixes at runtime based on linter violations.
  • [INDIRECT_PROMPT_INJECTION]: The automated repair pipeline creates an attack surface where untrusted data (project source code) is processed by linters and then fed into a sub-agent for remediation.
  • Ingestion points: Any project files being edited or created (Python, TypeScript, Shell, YAML, etc.).
  • Boundary markers: The documentation does not specify explicit boundary markers or 'ignore' instructions for the sub-agent prompts.
  • Capability inventory: The system executes shell scripts via hooks and performs file-write operations through the claude -p sub-agent.
  • Sanitization: Linter output is structured as JSON before being passed to the sub-agent, though the sub-agent must still process the original code context to perform fixes.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs users to install various external CLI tools and linters (e.g., ruff, uv, biome, hadolint, jaq) using system package managers like Homebrew.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — plankton-code-quality