ce-pov
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill's 'Cross-Model Panel' feature is designed to send repository content, conversation history, and framed questions to external AI providers (Anthropic, OpenAI, xAI) via their respective CLI tools (claude, codex, grok, etc.) to perform comparative assessments. While governed by configuration and user 'summons', this represents a significant channel for project context egress to third-party services.
- [COMMAND_EXECUTION]: The skill frequently executes shell commands and external binaries, including
git rev-parsefor repository resolution,opensslfor directory entropy, and various model CLIs for remote inference. It also uses administrative tools likeicacls(on Windows) andpsfor process management. - [DYNAMIC_EXECUTION]: The
scripts/peer-job-runner.pyscript allows the agent to launch and supervise background worker processes with dynamically constructed argument lists. The script is used to execute thecross-model-pov.shlogic for each participating model. - [PERSISTENCE]: The
scripts/peer-job-runner.pyutility implements a detached job execution system. It uses double-forking on POSIX systems and Windows Job Objects with theDETACHED_PROCESSflag to ensure that background tasks (such as long-running LLM calls) can complete independently of the parent agent's immediate lifecycle. This allows processes to persist and be reaped or queried in subsequent sessions. - [INDIRECT_PROMPT_INJECTION]: The skill is intended to judge external documents, approach sets, and other user-supplied subjects. This introduces an indirect prompt injection surface where a processed document could contain malicious instructions. The skill attempts to mitigate this by providing 'persona' instructions to peer models that explicitly mandate treating the payload as data rather than instructions.
Audit Metadata