ce-pov

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill's 'Cross-Model Panel' feature is designed to send repository content, conversation history, and framed questions to external AI providers (Anthropic, OpenAI, xAI) via their respective CLI tools (claude, codex, grok, etc.) to perform comparative assessments. While governed by configuration and user 'summons', this represents a significant channel for project context egress to third-party services.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands and external binaries, including git rev-parse for repository resolution, openssl for directory entropy, and various model CLIs for remote inference. It also uses administrative tools like icacls (on Windows) and ps for process management.
  • [DYNAMIC_EXECUTION]: The scripts/peer-job-runner.py script allows the agent to launch and supervise background worker processes with dynamically constructed argument lists. The script is used to execute the cross-model-pov.sh logic for each participating model.
  • [PERSISTENCE]: The scripts/peer-job-runner.py utility implements a detached job execution system. It uses double-forking on POSIX systems and Windows Job Objects with the DETACHED_PROCESS flag to ensure that background tasks (such as long-running LLM calls) can complete independently of the parent agent's immediate lifecycle. This allows processes to persist and be reaped or queried in subsequent sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to judge external documents, approach sets, and other user-supplied subjects. This introduces an indirect prompt injection surface where a processed document could contain malicious instructions. The skill attempts to mitigate this by providing 'persona' instructions to peer models that explicitly mandate treating the payload as data rather than instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 04:11 PM
Security Audit — agent-trust-hub — ce-pov