ce-promote

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands including git log, git diff, and gh pr view to extract feature context from the repository's version control history and GitHub metadata. It also executes local spiral CLI commands to generate copy.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to install the @every-env/spiral-cli package via npx, which downloads and executes code from the npm registry to enable enhanced drafting capabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted text from PR bodies, commit messages, and changelogs to inform its drafting process.\n
  • Ingestion points: gh pr view --json title,body,url, git log --oneline, and local CHANGELOG.md files.\n
  • Boundary markers: Absent; the skill does not use specific delimiters or instructions to ignore potential commands embedded within the ingested data.\n
  • Capability inventory: Shell command execution (git, gh, spiral), file system writes (.compound-engineering/config.local.yaml), and network access via the Spiral CLI.\n
  • Sanitization: None; the skill directly skims PR bodies and git logs for content generation.\n- [PERSISTENCE]: The skill modifies the repository's local Git exclude file (.git/info/exclude) to persistently ignore local configuration files containing user preferences (like the Spiral opt-out flag), ensuring these settings remain local across sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:21 AM
Security Audit — agent-trust-hub — ce-promote