plankton-code-quality
Warn
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from a third-party GitHub source (
https://github.com/alexfazio/plankton.git) to obtain the operational logic and shell scripts. - [COMMAND_EXECUTION]: Employs
PreToolUse,PostToolUse, andStophooks to automatically execute shell scripts (multi_linter.sh,protect_linter_configs.sh,stop_config_guardian.sh) on every file edit. - [REMOTE_CODE_EXECUTION]: The workflow involves downloading scripts from an external source and executing them as system hooks, providing a path for unverified code to run within the local environment with the agent's permissions.
- [PROMPT_INJECTION]: Instructions explicitly override the agent's default operational constraints by blocking the use of standard package managers (e.g.,
pip,npm,yarn) and enforcing specific alternatives (uv,bun). - [DATA_EXFILTRATION]: The Phase 3 architecture delegates code fixes to a subprocess by passing violation data in JSON format; while intended for linting, this mechanism creates a path for file-derived data to be processed by secondary model instances without direct user oversight.
Audit Metadata