ce-sweep

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted feedback content from external sources including Slack, GitHub Issues, and Email. This creates an attack surface for indirect prompt injection where malicious instructions could be embedded in user feedback.
  • Ingestion points: System fetches feedback via Slack (references/sources/slack.md), GitHub (references/sources/github-issues.md), and Email (references/sources/email.md).
  • Boundary markers: The skill explicitly instructs the agent and sub-agents to treat feedback content (body, title, media filenames) as data and never as instructions (SKILL.md, references/agents/media-analyzer.md).
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, enabling it to modify the repository and commit changes.
  • Sanitization: The skill employs summarization techniques rather than verbatim reproduction of untrusted content and redacts content when the sensitive flag is set.
  • [COMMAND_EXECUTION]: The skill uses shell commands via git and the GitHub CLI (gh) for fix verification and repository management.
  • Evidence: Phase 2f in references/run.md implements fix verification. To prevent command or argument injection, the skill enforces strict regex validation (#?\d+ or [0-9a-f]{7,40}) on external identifiers before they are passed to shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill downloads media files from configured feedback sources and sends them to OpenAI's transcription API for analysis.
  • Evidence: scripts/analyze_riffrec_zip.py contains a transcribe_media function that uses curl to interact with https://api.openai.com/v1/audio/transcriptions. This is a legitimate function for the skill's purpose and utilizes a well-known service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:22 AM
Security Audit — agent-trust-hub — ce-sweep