ce-doc-review
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted document content, which serves as an entry point for potential malicious instructions. These instructions could attempt to subvert the review process or abuse the skill's capabilities. Ingestion occurs in
references/subagent-template.mdthrough the interpolation of document content into the{document_content}variable. While boundary markers are used in the template, there is no explicit sanitization of the content. The skill's capabilities include modifying local files via the platform's edit tool and executing detached processes via a custom runner. - [DATA_EXFILTRATION]: Full document content is transmitted to external AI model providers including OpenAI, Anthropic, xAI, and Cursor during cross-model judgment passes. This egress is a core, documented feature designed to provide independent review corroboration, as described in
references/cross-model-review.mdand implemented inscripts/cross-model-doc-review.sh. - [COMMAND_EXECUTION]: The skill utilizes a custom management script,
scripts/peer-job-runner.py, to launch and supervise detached processes for external model CLI tools. This implementation constructs command lines dynamically inscripts/cross-model-doc-review.sh. To mitigate risks, the runner includes detailed ownership and permission checks (0700/0600) to ensure job data privacy and process integrity. - [EXTERNAL_DOWNLOADS]: The
scripts/packs-resolve.pycomponent can be configured to fetch 'Compound Packs' from remote Git repositories usinggit clonebased on the repository's CE configuration files.
Audit Metadata