ce-brainstorm

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on several scripts that execute shell commands. scripts/peer-job-runner.py manages detached background tasks using subprocess and os.setsid(). scripts/packs-resolve.py invokes git to resolve external packages. scripts/elevation-dispatch.sh calls the claude CLI for elevated reasoning tasks. These executions are core to the skill's functionality and are called with specific parameters defined in the instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository (via the grounding scout) and from Slack (via the Slack researcher). This creates a vulnerability surface where malicious instructions could be embedded in the processed data. However, the skill includes explicit mitigations:
  • Ingestion points: references/dialogue.md (repo files) and references/agents/slack-researcher.md (Slack messages).
  • Capabilities: The agent can write unified plan artifacts and execute background jobs via peer-job-runner.py.
  • Sanitization: references/agents/slack-researcher.md includes a dedicated 'Untrusted Input Handling' section directing the agent to ignore instructions inside Slack messages. references/reasoning-elevation.md (R20) further instructs the agent to treat research evidence as untrusted data.
  • Boundary markers: The grounding dossier uses structured gists and file pointers to delimit content.
  • [EXTERNAL_DOWNLOADS]: The scripts/packs-resolve.py script performs git clone operations to fetch 'Compound Packs' as defined in the repository's configuration. This involves downloading code from external sources (primarily GitHub).
  • [DYNAMIC_EXECUTION]: The skill features 'Model Elevation' (references/reasoning-elevation.md), which dispatches specific reasoning steps to a user-selected model. It also runs a local Node.js web server (scripts/light-webserver.js) to serve HTML/JS artifacts for visual brainstorming probes. The web server includes security features such as a session token for authorization and path traversal prevention using realpath verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:39 AM
Security Audit — agent-trust-hub — ce-brainstorm