ce-compound
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill resolves 'Compound Packs' by cloning git repositories from GitHub. Evidence in
scripts/packs-resolve.pyshows usage ofgit cloneandgit fetch. This targets a well-known service and uses the repository's own configuration as the source list. - [COMMAND_EXECUTION]: The skill extensively uses shell commands and Python scripts for its workflow. It executes internal scripts like
packs-resolve.py,validate-frontmatter.py,validate-doc-claims.py, and the session-history discovery suite (discover-sessions.sh,extract-metadata.py). These are used to validate artifacts and process local metadata. - [DYNAMIC_EXECUTION]: Several Python scripts are executed at runtime via the agent's shell capability to process data and validate doc claims.
scripts/packs-resolve.pyandscripts/validate-doc-claims.pyusesubprocess.run()to interface with thegitbinary. These scripts include security-focused logic to ensure that scratch directories and caches are owned by the effective user and are not symlinks to unauthorized locations. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of agent session histories (
.jsonlfiles) from multiple tools (Claude Code, Codex, Cursor, Pi). This creates a surface for indirect injection if a session contains malicious instructions. However, thereferences/agents/session-historian.mdsubagent prompt contains strict guardrails requiring summarization, forbidding the reproduction of tool inputs, and preventing the execution of further skills from the subagent context. - [DATA_EXFILTRATION]: The skill accesses highly sensitive data including user session histories containing past commands and tool outputs. The discovery logic in
scripts/session-history/discover-sessions.shtargets local configuration directories (~/.claude,~/.codex, etc.). However, there is no evidence of this data being sent to untrusted external domains; it is processed locally to generate markdown documentation within the repository's own<root>/solutions/folder.
Audit Metadata