ce-compound-refresh

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a test case in references/evals.yaml that specifically simulates a prompt injection attempt to ignore instructions. This is a security feature used for validation and does not pose a threat to the user or system.
  • [DATA_EXFILTRATION]: Instructions in both SKILL.md and references/contract.yaml strictly require the redaction of secrets, tokens, and credentials from all artifacts and reports generated by the skill.
  • [COMMAND_EXECUTION]: The execution rules in SKILL.md explicitly prohibit the use of shell commands such as bash, cat, and grep for file system operations, requiring the agent to use safer, dedicated platform tools instead.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — ce-compound-refresh