plankton-code-quality

Warn

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from a third-party GitHub source (https://github.com/alexfazio/plankton.git) to obtain the operational logic and shell scripts.
  • [COMMAND_EXECUTION]: Employs PreToolUse, PostToolUse, and Stop hooks to automatically execute shell scripts (multi_linter.sh, protect_linter_configs.sh, stop_config_guardian.sh) on every file edit.
  • [REMOTE_CODE_EXECUTION]: The workflow involves downloading scripts from an external source and executing them as system hooks, providing a path for unverified code to run within the local environment with the agent's permissions.
  • [PROMPT_INJECTION]: Instructions explicitly override the agent's default operational constraints by blocking the use of standard package managers (e.g., pip, npm, yarn) and enforcing specific alternatives (uv, bun).
  • [DATA_EXFILTRATION]: The Phase 3 architecture delegates code fixes to a subprocess by passing violation data in JSON format; while intended for linting, this mechanism creates a path for file-derived data to be processed by secondary model instances without direct user oversight.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — plankton-code-quality