plankton-code-quality

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation describes the use of shell scripts (multi_linter.sh, protect_linter_configs.sh, stop_config_guardian.sh) as PreToolUse, PostToolUse, and Stop hooks. These scripts actively monitor and intercept file edits and shell commands to enforce quality standards and block legacy tools.
  • [DYNAMIC_EXECUTION]: The skill utilizes a delegation phase that spawns claude -p subprocesses. These sub-agents are dynamically invoked to fix code violations based on JSON output from linters, using a tiered routing system that selects model versions based on issue complexity.
  • [INDIRECT_PROMPT_INJECTION]: The automated workflow presents an indirect prompt injection surface by feeding file contents and linter violations directly into a subprocess agent.
  • Ingestion points: Every file edit or write operation performed by the main agent triggers the collection of data for the multi_linter.sh hook.
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the sub-agent from following instructions embedded within the code files it is attempting to fix.
  • Capability inventory: The skill facilitates subprocess spawning (claude -p), broad filesystem monitoring via hooks, and the ability to block or redirect package manager commands.
  • Sanitization: No evidence is provided regarding the sanitization or escaping of linter results or source code before it is passed to the delegation subprocess.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — plankton-code-quality