ce-brainstorm
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on several scripts that execute shell commands.
scripts/peer-job-runner.pymanages detached background tasks usingsubprocessandos.setsid().scripts/packs-resolve.pyinvokesgitto resolve external packages.scripts/elevation-dispatch.shcalls theclaudeCLI for elevated reasoning tasks. These executions are core to the skill's functionality and are called with specific parameters defined in the instructions. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository (via the grounding scout) and from Slack (via the Slack researcher). This creates a vulnerability surface where malicious instructions could be embedded in the processed data. However, the skill includes explicit mitigations:
- Ingestion points:
references/dialogue.md(repo files) andreferences/agents/slack-researcher.md(Slack messages). - Capabilities: The agent can write unified plan artifacts and execute background jobs via
peer-job-runner.py. - Sanitization:
references/agents/slack-researcher.mdincludes a dedicated 'Untrusted Input Handling' section directing the agent to ignore instructions inside Slack messages.references/reasoning-elevation.md(R20) further instructs the agent to treat research evidence as untrusted data. - Boundary markers: The grounding dossier uses structured gists and file pointers to delimit content.
- [EXTERNAL_DOWNLOADS]: The
scripts/packs-resolve.pyscript performsgit cloneoperations to fetch 'Compound Packs' as defined in the repository's configuration. This involves downloading code from external sources (primarily GitHub). - [DYNAMIC_EXECUTION]: The skill features 'Model Elevation' (
references/reasoning-elevation.md), which dispatches specific reasoning steps to a user-selected model. It also runs a local Node.js web server (scripts/light-webserver.js) to serve HTML/JS artifacts for visual brainstorming probes. The web server includes security features such as a session token for authorization and path traversal prevention usingrealpathverification.
Audit Metadata