ce-setup

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes bundled Bash and Python scripts (scripts/check-health and scripts/packs-resolve.py) to perform environment diagnostics, check for tool availability, and resolve project-specific configurations.
  • [EXTERNAL_DOWNLOADS]: The skill fetches 'Compound Packs' (collections of markdown-based rules) from remote Git repositories. The URLs for these repositories are defined by the user in the project's .compound-engineering/config.yaml file. The skill uses git ls-remote, git fetch, and git clone to retrieve these resources into a local cache directory.
  • [PERSISTENCE]: The skill offers to modify project-level agent instruction files (such as AGENTS.md, CLAUDE.md, or GEMINI.md) to add standing instructions. These instructions persist across agent sessions to guide behavior regarding the use of specific tools (e.g., ce-compound, ce-noslop) and the capture of project knowledge. Each modification is previewed and requires explicit user approval.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes 'packs' which contain markdown files with specific frontmatter (title, applies_when). These files are designed to influence the reasoning and planning behavior of other skills in the Compound Engineering ecosystem. The skill includes safety checks to ensure rule files do not contain symlinks that escape the source directory.
  • [SAFE]: The skill identifies and references well-known services and organizations, including github.com/vercel-labs/agent-browser, as part of its dependency reporting. All network operations (Git) are performed with standard timeouts and non-interactive flags to prevent hanging.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:27 AM
Security Audit — agent-trust-hub — ce-setup