plankton-code-quality

Warn

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses PreToolUse, PostToolUse, and Stop hooks to execute multiple shell scripts (multi_linter.sh, protect_linter_configs.sh, stop_config_guardian.sh) automatically whenever the agent modifies files or ends a session.
  • [COMMAND_EXECUTION]: It spawns autonomous claude -p subprocesses to resolve code violations, delegating tasks to various model tiers (Haiku, Sonnet, Opus) based on issue complexity.
  • [COMMAND_EXECUTION]: The skill implements a command-blocking mechanism that intercepts standard package manager calls (pip, npm, yarn, pnpm, poetry) and forces the agent to use specific alternatives (uv, bun), which overrides standard environment behavior.
  • [REMOTE_CODE_EXECUTION]: The setup process involves installing multiple external dependencies via brew install jaq ruff uv and uv sync --all-extras.
  • [EXTERNAL_DOWNLOADS]: Fetches and installs a wide array of third-party linting and formatting tools from various registries (PyPI, NPM, Homebrew) including Ruff, Biome, Shellcheck, Yamllint, and Hadolint.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project files and linter output, then passes this untrusted data to a subprocess model for automated fixing, creating a vulnerability surface where malicious code could influence the subprocess.
  • Ingestion points: Modified project files and structured JSON violation reports.
  • Boundary markers: No explicit markers or "ignore embedded instructions" warnings are documented for the subprocess delegation.
  • Capability inventory: The system can perform file writes, tool execution, and model invocation across all scripts (SKILL.md).
  • Sanitization: No sanitization or validation of external code content is described before it is interpolated into the subprocess prompt.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — plankton-code-quality