ce-doc-review

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Specialized persona agents are permitted to use shell tools (e.g., bash, grep, git log) to gather context from the local codebase. This capability is strictly regulated by instructions in subagent-template.md and individual persona files, which mandate that agents remain operationally read-only and forbid the use of mutating tools.- [PROMPT_INJECTION]: The skill processes untrusted requirements and plan documents, which presents an indirect prompt injection surface.
  • Ingestion points: External document content is ingested during Phase 1 and passed to analyst sub-agents (SKILL.md).
  • Boundary markers: Data is encapsulated within defined tags (<review-context>) in the sub-agent prompt template.
  • Capability inventory: The orchestrator can perform file writes via platform-provided edit tools to apply corrections or append notes; sub-agents are restricted to read-only codebase exploration tools.
  • Sanitization: Agent outputs are constrained by a strict JSON schema and processed through a synthesis pipeline that validates and deduplicates findings before presentation.- [SAFE]: The system features a 'Protected Artifacts' rule that explicitly prevents the automated deletion of critical project documentation (e.g., brainstorms and plans). Additionally, automated fixes are restricted to low-risk, mechanical corrections at the highest confidence level, while all other findings require user oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 09:15 PM
Security Audit — agent-trust-hub — ce-doc-review