ce-optimize

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes arbitrary measurement commands defined in the optimization specification (spec.yaml) via scripts/measure.sh. While this is core to the optimization process, it allows for the execution of arbitrary shell commands within the environment.
  • [DATA_EXFILTRATION]: The script scripts/experiment-worktree.sh automatically copies .env files from the repository root to each experiment-specific worktree directory (.worktrees/optimize-<spec>-exp-<NNN>/). This behavior increases the footprint of potentially sensitive environment variables and credentials in temporary, gitignored directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests repository content, documentation from the solutions/ directory, and past experiment results to generate new hypotheses and learnings using subagents (learnings-researcher.md, repo-researcher.md).
  • Ingestion points: Repository source code, documentation files in solutions/, and external YAML specifications.
  • Boundary markers: Uses XML-style tags (e.g., <rubric>, <experiment-context>) in prompt templates to separate instructions from data.
  • Capability inventory: The system has the capability to execute shell commands (measure.sh), perform git operations (experiment-worktree.sh), and write to the file system.
  • Sanitization: No explicit sanitization or filtering of external data is performed before it is interpolated into subagent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 08:26 PM
Security Audit — agent-trust-hub — ce-optimize