ce-promote
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands including
git log,git diff, andgh pr viewto extract feature context from the repository's version control history and GitHub metadata. It also executes localspiralCLI commands to generate copy.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to install the@every-env/spiral-clipackage vianpx, which downloads and executes code from the npm registry to enable enhanced drafting capabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted text from PR bodies, commit messages, and changelogs to inform its drafting process.\n - Ingestion points:
gh pr view --json title,body,url,git log --oneline, and localCHANGELOG.mdfiles.\n - Boundary markers: Absent; the skill does not use specific delimiters or instructions to ignore potential commands embedded within the ingested data.\n
- Capability inventory: Shell command execution (
git,gh,spiral), file system writes (.compound-engineering/config.local.yaml), and network access via the Spiral CLI.\n - Sanitization: None; the skill directly skims PR bodies and git logs for content generation.\n- [PERSISTENCE]: The skill modifies the repository's local Git exclude file (
.git/info/exclude) to persistently ignore local configuration files containing user preferences (like the Spiral opt-out flag), ensuring these settings remain local across sessions.
Audit Metadata