ce-ideate

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands for environment discovery and artifact management. Specifically, references/grounding.md contains a bash script block that initializes a private scratch directory using mkdir -p and chmod 700. It also uses tools like git rev-parse and git remote to resolve repository context and gh or orca CLIs to fetch issue data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources including web search results, Slack threads, and issue tracker content. While it provides specific guardrails against this threat, the ingestion of external content presents an attack surface.
  • Ingestion points: Untrusted content enters the context via references/grounding.md (Web research and Issue intelligence) and references/agents/slack-researcher.md (Slack search).
  • Boundary markers: The skill employs structural delimiters such as <grounding>, <constraints>, and <background> to separate data types when dispatching ideation sub-agents in references/divergent-ideation.md.
  • Capability inventory: The skill possesses capabilities to execute shell commands, write files to temporary directories, and perform network requests to authenticated organizational services (Slack, GitHub, Linear).
  • Sanitization: Explicit "Untrusted Input Handling" instructions are included in references/agents/slack-researcher.md and references/agents/web-researcher.md, directing agents to extract factual data while ignoring any embedded instructions or system prompt imitations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:11 AM
Security Audit — agent-trust-hub — ce-ideate