ce-ideate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands for environment discovery and artifact management. Specifically,
references/grounding.mdcontains a bash script block that initializes a private scratch directory usingmkdir -pandchmod 700. It also uses tools likegit rev-parseandgit remoteto resolve repository context andghororcaCLIs to fetch issue data. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources including web search results, Slack threads, and issue tracker content. While it provides specific guardrails against this threat, the ingestion of external content presents an attack surface.
- Ingestion points: Untrusted content enters the context via
references/grounding.md(Web research and Issue intelligence) andreferences/agents/slack-researcher.md(Slack search). - Boundary markers: The skill employs structural delimiters such as
<grounding>,<constraints>, and<background>to separate data types when dispatching ideation sub-agents inreferences/divergent-ideation.md. - Capability inventory: The skill possesses capabilities to execute shell commands, write files to temporary directories, and perform network requests to authenticated organizational services (Slack, GitHub, Linear).
- Sanitization: Explicit "Untrusted Input Handling" instructions are included in
references/agents/slack-researcher.mdandreferences/agents/web-researcher.md, directing agents to extract factual data while ignoring any embedded instructions or system prompt imitations.
Audit Metadata