ce-compound-refresh
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits and processes external documentation files which could potentially contain malicious instructions intended to subvert agent logic. This is an inherent risk in the auditing of user-controlled content.\n
- Ingestion points: The skill reads Markdown files from the
<root>/solutions/directory and referenced guidance files (e.g.,SKILL.md, runbooks) as specified inreferences/investigate.md.\n - Boundary markers: While the skill uses specific prompt instructions for subagents, it lacks robust structural delimiters or sanitization to prevent the agent from following instructions embedded in the documents it analyzes.\n
- Capability inventory: The skill has permissions to write to the filesystem, delete files, and execute git commands, which could be abused if an injection is successful.\n
- Sanitization: There is no evidence of filtering or escaping logic for the content read from external documents before it is processed by subagents.\n- [DYNAMIC_EXECUTION]: The skill executes bundled Python scripts (
scripts/validate-frontmatter.pyandscripts/validate-doc-claims.py) to perform validation tasks during the refresh cycle. These scripts are invoked via the shell as part of the normal execution flow defined inreferences/per-action-flows.md.\n- [COMMAND_EXECUTION]: Thescripts/validate-doc-claims.pyscript executes severalgitcommands (includingrev-parse,cat-file, andmerge-base) through thesubprocessmodule to verify the existence of repository paths and the reachability of commit SHAs mentioned in the documentation.
Audit Metadata