ce-work
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on system commands for repository management, Git operations, and orchestrating external AI tools.
- Evidence:
scripts/unit-workspace.pyandscripts/peer-job-runner.pyusesubprocess.runandsubprocess.Popento managegit,gh, and various AI agent CLIs (e.g.,codex,claude,grok). These operations are fundamental to the skill's primary purpose. - [DYNAMIC_EXECUTION]: Implementation verification involves running user-defined or plan-defined commands at runtime.
- Evidence:
scripts/unit_workspace_transaction.pyexecutes verification commands provided in the implementation plan viasubprocess.runto validate the resulting code changes. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted implementation plans that influence the behavior of worker subagents.
- Ingestion points:
SKILL.md(Phase 0) andreferences/work-intake.mddescribe the intake of plans and prompts. - Boundary markers: Present.
references/agents/implementation-worker.mdandreferences/cross-model-execution.mduse structural separators (e.g.,--- BOUNDED IMPLEMENTATION UNIT PACKET ---) to isolate worker instructions. - Capability inventory:
scripts/unit-workspace.pyand its modules can execute arbitrary shell commands for verification and Git operations. - Sanitization: Present. The skill uses
safe_idvalidation for identifiers and aredact_streamfunction inscripts/cross-model-work.shto remove sensitive values from logs.
Audit Metadata