ce-compound

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill resolves 'Compound Packs' by cloning git repositories from GitHub. Evidence in scripts/packs-resolve.py shows usage of git clone and git fetch. This targets a well-known service and uses the repository's own configuration as the source list.
  • [COMMAND_EXECUTION]: The skill extensively uses shell commands and Python scripts for its workflow. It executes internal scripts like packs-resolve.py, validate-frontmatter.py, validate-doc-claims.py, and the session-history discovery suite (discover-sessions.sh, extract-metadata.py). These are used to validate artifacts and process local metadata.
  • [DYNAMIC_EXECUTION]: Several Python scripts are executed at runtime via the agent's shell capability to process data and validate doc claims. scripts/packs-resolve.py and scripts/validate-doc-claims.py use subprocess.run() to interface with the git binary. These scripts include security-focused logic to ensure that scratch directories and caches are owned by the effective user and are not symlinks to unauthorized locations.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of agent session histories (.jsonl files) from multiple tools (Claude Code, Codex, Cursor, Pi). This creates a surface for indirect injection if a session contains malicious instructions. However, the references/agents/session-historian.md subagent prompt contains strict guardrails requiring summarization, forbidding the reproduction of tool inputs, and preventing the execution of further skills from the subagent context.
  • [DATA_EXFILTRATION]: The skill accesses highly sensitive data including user session histories containing past commands and tool outputs. The discovery logic in scripts/session-history/discover-sessions.sh targets local configuration directories (~/.claude, ~/.codex, etc.). However, there is no evidence of this data being sent to untrusted external domains; it is processed locally to generate markdown documentation within the repository's own <root>/solutions/ folder.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 03:40 PM
Security Audit — agent-trust-hub — ce-compound