plankton-code-quality
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill configures PreToolUse, PostToolUse, and Stop hooks to execute local shell scripts (multi_linter.sh, protect_linter_configs.sh, stop_config_guardian.sh) on every file modification.
- [REMOTE_CODE_EXECUTION]: The system automatically spawns secondary AI agents via claude -p subprocesses to apply code fixes, granting the system autonomous write access to the filesystem based on AI-generated output.
- [COMMAND_EXECUTION]: The skill implements a policy that intercepts and blocks standard package management commands (pip, npm, poetry, etc.) through Bash hooks to enforce the use of specific alternatives (uv, bun).
- [PROMPT_INJECTION]: An indirect prompt injection surface exists where structured JSON containing violation messages (which include snippets from the edited code) is passed to secondary Claude processes, potentially influencing the behavior of the subprocess agent.
- [PROMPT_INJECTION]: The skill includes instructions to the agent to protect its own linter configurations from modification, creating a conflict where the agent is told to disregard or block certain user-directed file edits.
Audit Metadata