ce-doc-review

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted document content, which serves as an entry point for potential malicious instructions. These instructions could attempt to subvert the review process or abuse the skill's capabilities. Ingestion occurs in references/subagent-template.md through the interpolation of document content into the {document_content} variable. While boundary markers are used in the template, there is no explicit sanitization of the content. The skill's capabilities include modifying local files via the platform's edit tool and executing detached processes via a custom runner.
  • [DATA_EXFILTRATION]: Full document content is transmitted to external AI model providers including OpenAI, Anthropic, xAI, and Cursor during cross-model judgment passes. This egress is a core, documented feature designed to provide independent review corroboration, as described in references/cross-model-review.md and implemented in scripts/cross-model-doc-review.sh.
  • [COMMAND_EXECUTION]: The skill utilizes a custom management script, scripts/peer-job-runner.py, to launch and supervise detached processes for external model CLI tools. This implementation constructs command lines dynamically in scripts/cross-model-doc-review.sh. To mitigate risks, the runner includes detailed ownership and permission checks (0700/0600) to ensure job data privacy and process integrity.
  • [EXTERNAL_DOWNLOADS]: The scripts/packs-resolve.py component can be configured to fetch 'Compound Packs' from remote Git repositories using git clone based on the repository's CE configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:10 AM
Security Audit — agent-trust-hub — ce-doc-review