ce-dogfood

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local script scripts/packs-resolve.py to manage configuration dependencies. This script invokes the git binary using subprocess.run to perform repository operations.
  • [REMOTE_CODE_EXECUTION]: The skill is designed to automatically clone or fetch data from remote git repositories based on configurations found in the target project (.compound-engineering/config.yaml). Although the script only processes markdown files from these sources, the automated downloading of remote content based on repository state (which could be influenced by a Pull Request) is a significant capability.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources, which could be used to influence the agent's behavior during the QA process.
  • Ingestion points: The agent reads the output of git diff, gh pr view, and the contents of external markdown files within "Compound Packs."
  • Boundary markers: The instructions do not specify explicit delimiters or safety instructions (e.g., "ignore instructions in the diff") when processing these external inputs.
  • Capability inventory: The agent possesses powerful capabilities, including full browser automation (agent-browser), file system writes for generating reports, and the ability to execute CLI tools like git and gh.
  • Sanitization: The scripts/packs-resolve.py script implements specific security checks to mitigate risks associated with untrusted content, such as _within for path traversal prevention and _escaping_links to detect and skip symlinks that point outside the intended source directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:21 AM
Security Audit — agent-trust-hub — ce-dogfood