ce-plan

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages detached tasks via scripts/peer-job-runner.py and scripts/elevation-dispatch.sh. These scripts execute commands like git and the claude CLI. Command-line construction is hardened; for instance, the Claude CLI is invoked with --safe-mode and a restricted set of read-only tools to prevent unintended actions during model elevation.- [EXTERNAL_DOWNLOADS]: The scripts/packs-resolve.py script clones Git repositories to resolve configuration-defined 'Compound Packs.' It uses the --end-of-options flag in Git commands to mitigate argument injection risks from potentially malicious URLs in config files.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant ingestion surface for untrusted data. * Ingestion points: The skill reads local repository files (via references/research.md), Slack threads (slack-researcher.md), and web pages (web-researcher.md). * Boundary markers: references/reasoning-elevation.md includes a mandatory 'R20' rule instructing sub-agents to treat all evidence as untrusted data to interpret, not instructions to obey. * Capability inventory: Potential exploitable capabilities include subprocess execution via the bundled scripts. * Sanitization: The architecture requires the session model to validate sub-agent outputs before integration, ensuring they conform to expected plan structures rather than being redirected instructions.- [SAFE]: scripts/peer-job-runner.py implements advanced security practices for managing temporary files in shared directories (like /tmp). It uses os.open with O_NOFOLLOW and verifies the file owner's UID against the current user before reading any job state, preventing symlink-based data harvesting or tampering in multi-user systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:10 AM
Security Audit — agent-trust-hub — ce-plan