cass

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of local command execution. It invokes the cass binary for status, indexing, search, and analytics. It also uses system utilities like jq for JSON processing, timeout for process management, and ssh/rsync for remote operations. The scripts/recover.sh script manages process lifecycles using setsid, disown, and signal trapping.
  • [DYNAMIC_EXECUTION]: The skill enables resuming past agent sessions through the cass resume command. It generates shell-escaped commands for various agent harnesses (Claude Code, Codex, Gemini) and supports direct process replacement via the --exec flag or evaluation of generated commands via eval in the shell.
  • [REMOTE_CODE_EXECUTION]: The skill implements a 'Cross-Machine Search' feature that executes the cass binary on remote hosts using ssh. The scripts/multi_machine_search.sh script performs parallel fan-out searches by piping queries to remote ssh sessions, using stdin to safely pass the search terms.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by processing data from past session logs.
  • Ingestion points: Reads .jsonl session files from directories like ~/.claude/projects/, ~/.codex/sessions/, and ~/.gemini/ via cass view, cass expand, and prompt_miner.py.
  • Boundary markers: The instructions suggest using jq to filter specific messages, but the content itself is not wrapped in protective delimiters.
  • Capability inventory: The skill has the ability to execute commands locally and remotely via ssh and the cass binary.
  • Sanitization: Content is extracted and presented to the agent without specific escaping of potential prompt injection sequences.
  • [EXTERNAL_DOWNLOADS]: The cass models install command downloads MiniLM model bundles from HuggingFace. As HuggingFace is a well-known and established service for hosting machine learning assets, this is documented as a neutral operational discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:09 AM
Security Audit — agent-trust-hub — cass