ce-compound-refresh

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill audits and processes external documentation files which could potentially contain malicious instructions intended to subvert agent logic. This is an inherent risk in the auditing of user-controlled content.\n
  • Ingestion points: The skill reads Markdown files from the <root>/solutions/ directory and referenced guidance files (e.g., SKILL.md, runbooks) as specified in references/investigate.md.\n
  • Boundary markers: While the skill uses specific prompt instructions for subagents, it lacks robust structural delimiters or sanitization to prevent the agent from following instructions embedded in the documents it analyzes.\n
  • Capability inventory: The skill has permissions to write to the filesystem, delete files, and execute git commands, which could be abused if an injection is successful.\n
  • Sanitization: There is no evidence of filtering or escaping logic for the content read from external documents before it is processed by subagents.\n- [DYNAMIC_EXECUTION]: The skill executes bundled Python scripts (scripts/validate-frontmatter.py and scripts/validate-doc-claims.py) to perform validation tasks during the refresh cycle. These scripts are invoked via the shell as part of the normal execution flow defined in references/per-action-flows.md.\n- [COMMAND_EXECUTION]: The scripts/validate-doc-claims.py script executes several git commands (including rev-parse, cat-file, and merge-base) through the subprocess module to verify the existence of repository paths and the reachability of commit SHAs mentioned in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:17 AM
Security Audit — agent-trust-hub — ce-compound-refresh