plankton-code-quality
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a suite of environment hooks (
PreToolUse,PostToolUse, andStop) to execute local shell scripts such asmulti_linter.shandprotect_linter_configs.shwhenever file modifications occur. - [DYNAMIC_EXECUTION]: Implements a three-phase architecture that spawns
claude -psubprocesses to automatically generate and apply code fixes at runtime based on linter violations. - [INDIRECT_PROMPT_INJECTION]: The automated repair pipeline creates an attack surface where untrusted data (project source code) is processed by linters and then fed into a sub-agent for remediation.
- Ingestion points: Any project files being edited or created (Python, TypeScript, Shell, YAML, etc.).
- Boundary markers: The documentation does not specify explicit boundary markers or 'ignore' instructions for the sub-agent prompts.
- Capability inventory: The system executes shell scripts via hooks and performs file-write operations through the
claude -psub-agent. - Sanitization: Linter output is structured as JSON before being passed to the sub-agent, though the sub-agent must still process the original code context to perform fixes.
- [EXTERNAL_DOWNLOADS]: The documentation instructs users to install various external CLI tools and linters (e.g.,
ruff,uv,biome,hadolint,jaq) using system package managers like Homebrew.
Audit Metadata