ce-work

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on system commands for repository management, Git operations, and orchestrating external AI tools.
  • Evidence: scripts/unit-workspace.py and scripts/peer-job-runner.py use subprocess.run and subprocess.Popen to manage git, gh, and various AI agent CLIs (e.g., codex, claude, grok). These operations are fundamental to the skill's primary purpose.
  • [DYNAMIC_EXECUTION]: Implementation verification involves running user-defined or plan-defined commands at runtime.
  • Evidence: scripts/unit_workspace_transaction.py executes verification commands provided in the implementation plan via subprocess.run to validate the resulting code changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted implementation plans that influence the behavior of worker subagents.
  • Ingestion points: SKILL.md (Phase 0) and references/work-intake.md describe the intake of plans and prompts.
  • Boundary markers: Present. references/agents/implementation-worker.md and references/cross-model-execution.md use structural separators (e.g., --- BOUNDED IMPLEMENTATION UNIT PACKET ---) to isolate worker instructions.
  • Capability inventory: scripts/unit-workspace.py and its modules can execute arbitrary shell commands for verification and Git operations.
  • Sanitization: Present. The skill uses safe_id validation for identifiers and a redact_stream function in scripts/cross-model-work.sh to remove sensitive values from logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:57 AM
Security Audit — agent-trust-hub — ce-work