plankton-code-quality
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation describes the use of shell scripts (
multi_linter.sh,protect_linter_configs.sh,stop_config_guardian.sh) as PreToolUse, PostToolUse, and Stop hooks. These scripts actively monitor and intercept file edits and shell commands to enforce quality standards and block legacy tools. - [DYNAMIC_EXECUTION]: The skill utilizes a delegation phase that spawns
claude -psubprocesses. These sub-agents are dynamically invoked to fix code violations based on JSON output from linters, using a tiered routing system that selects model versions based on issue complexity. - [INDIRECT_PROMPT_INJECTION]: The automated workflow presents an indirect prompt injection surface by feeding file contents and linter violations directly into a subprocess agent.
- Ingestion points: Every file edit or write operation performed by the main agent triggers the collection of data for the
multi_linter.shhook. - Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the sub-agent from following instructions embedded within the code files it is attempting to fix.
- Capability inventory: The skill facilitates subprocess spawning (
claude -p), broad filesystem monitoring via hooks, and the ability to block or redirect package manager commands. - Sanitization: No evidence is provided regarding the sanitization or escaping of linter results or source code before it is passed to the delegation subprocess.
Audit Metadata