cass
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
sshto execute search queries on remote machines in parallel via thescripts/multi_machine_search.shscript. This is an intended feature for multi-agent fleet management and employs secure practices by passing queries through stdin to prevent shell injection. - [EXTERNAL_DOWNLOADS]: The
cass models installfunctionality downloads semantic model bundles from HuggingFace. As HuggingFace is a trusted organization for AI resources, this operation is considered safe and standard for the tool's semantic search capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes past AI agent session logs, which represents the ingestion of untrusted data. The skill mitigates this risk through extensive instructional guardrails that warn against auto-adopting retrieved instructions and mandate human verification of cited outcomes.
- Ingestion points: Agent session logs (
.jsonlfiles) are read from project and user directories bycassandscripts/prompt_miner.py. - Boundary markers: The skill documentation provides explicit warnings to treat history as evidence rather than doctrine and requires citation of source paths and lines.
- Capability inventory: Capabilities include file reading, network communication (SSH), and session resumption (
cass resume --exec). - Sanitization:
prompt_miner.pynormalizes whitespace, and thecasstool uses structured JSON for all machine-readable output to maintain clear data boundaries. - [DATA_EXFILTRATION]: The skill transmits search queries to remote hosts via SSH to facilitate cross-machine search. This data transfer is limited to the user's search terms and is a primary functional requirement of the fleet-wide search feature.
Audit Metadata