cass
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of local command execution. It invokes the
cassbinary for status, indexing, search, and analytics. It also uses system utilities likejqfor JSON processing,timeoutfor process management, andssh/rsyncfor remote operations. Thescripts/recover.shscript manages process lifecycles usingsetsid,disown, and signal trapping. - [DYNAMIC_EXECUTION]: The skill enables resuming past agent sessions through the
cass resumecommand. It generates shell-escaped commands for various agent harnesses (Claude Code, Codex, Gemini) and supports direct process replacement via the--execflag or evaluation of generated commands viaevalin the shell. - [REMOTE_CODE_EXECUTION]: The skill implements a 'Cross-Machine Search' feature that executes the
cassbinary on remote hosts usingssh. Thescripts/multi_machine_search.shscript performs parallel fan-out searches by piping queries to remotesshsessions, using stdin to safely pass the search terms. - [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by processing data from past session logs.
- Ingestion points: Reads
.jsonlsession files from directories like~/.claude/projects/,~/.codex/sessions/, and~/.gemini/viacass view,cass expand, andprompt_miner.py. - Boundary markers: The instructions suggest using
jqto filter specific messages, but the content itself is not wrapped in protective delimiters. - Capability inventory: The skill has the ability to execute commands locally and remotely via
sshand thecassbinary. - Sanitization: Content is extracted and presented to the agent without specific escaping of potential prompt injection sequences.
- [EXTERNAL_DOWNLOADS]: The
cass models installcommand downloads MiniLM model bundles from HuggingFace. As HuggingFace is a well-known and established service for hosting machine learning assets, this is documented as a neutral operational discovery.
Audit Metadata