ce-plan
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill manages detached tasks via
scripts/peer-job-runner.pyandscripts/elevation-dispatch.sh. These scripts execute commands likegitand theclaudeCLI. Command-line construction is hardened; for instance, the Claude CLI is invoked with--safe-modeand a restricted set of read-only tools to prevent unintended actions during model elevation.- [EXTERNAL_DOWNLOADS]: Thescripts/packs-resolve.pyscript clones Git repositories to resolve configuration-defined 'Compound Packs.' It uses the--end-of-optionsflag in Git commands to mitigate argument injection risks from potentially malicious URLs in config files.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant ingestion surface for untrusted data. * Ingestion points: The skill reads local repository files (viareferences/research.md), Slack threads (slack-researcher.md), and web pages (web-researcher.md). * Boundary markers:references/reasoning-elevation.mdincludes a mandatory 'R20' rule instructing sub-agents to treat all evidence as untrusted data to interpret, not instructions to obey. * Capability inventory: Potential exploitable capabilities include subprocess execution via the bundled scripts. * Sanitization: The architecture requires the session model to validate sub-agent outputs before integration, ensuring they conform to expected plan structures rather than being redirected instructions.- [SAFE]:scripts/peer-job-runner.pyimplements advanced security practices for managing temporary files in shared directories (like/tmp). It usesos.openwithO_NOFOLLOWand verifies the file owner's UID against the current user before reading any job state, preventing symlink-based data harvesting or tampering in multi-user systems.
Audit Metadata