ce-dogfood
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script
scripts/packs-resolve.pyto manage configuration dependencies. This script invokes thegitbinary usingsubprocess.runto perform repository operations. - [REMOTE_CODE_EXECUTION]: The skill is designed to automatically clone or fetch data from remote git repositories based on configurations found in the target project (
.compound-engineering/config.yaml). Although the script only processes markdown files from these sources, the automated downloading of remote content based on repository state (which could be influenced by a Pull Request) is a significant capability. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources, which could be used to influence the agent's behavior during the QA process.
- Ingestion points: The agent reads the output of
git diff,gh pr view, and the contents of external markdown files within "Compound Packs." - Boundary markers: The instructions do not specify explicit delimiters or safety instructions (e.g., "ignore instructions in the diff") when processing these external inputs.
- Capability inventory: The agent possesses powerful capabilities, including full browser automation (
agent-browser), file system writes for generating reports, and the ability to execute CLI tools likegitandgh. - Sanitization: The
scripts/packs-resolve.pyscript implements specific security checks to mitigate risks associated with untrusted content, such as_withinfor path traversal prevention and_escaping_linksto detect and skip symlinks that point outside the intended source directory.
Audit Metadata