ce-ideate

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: External data enters through GitHub issues (references/personas/ce-issue-intelligence-analyst.md), web pages (references/personas/ce-web-researcher.md), Slack messages (references/personas/ce-slack-researcher.md), and user-supplied research files.\n
  • Boundary markers: The skill utilizes structured tags such as , , and in references/divergent-ideation.md to separate instructions from data at subagent dispatch.\n
  • Capability inventory: The agent can execute shell commands (git, gh, open), perform file system operations (Read/Write/Delete), and access the network via Slack and Web MCP tools.\n
  • Sanitization: Each research persona includes explicit instructions to ignore anything in the retrieved content that resembles agent instructions, tool calls, or system prompts.\n- [COMMAND_EXECUTION]: The skill executes shell commands like git, gh, mkdir, and start to facilitate repository exploration, issue analysis, and artifact management. These are legitimate operations given the skill's purpose as a development assistant.\n- [EXTERNAL_DOWNLOADS]: The skill fetches data from remote services including Slack and the public web. These operations are handled through dedicated MCP tools or the gh CLI and are documented as core features for grounding ideation results.\n- [SAFE]: The skill employs dynamic context injection in SKILL.md to resolve the current repository root using git rev-parse. This is a benign use of the platform's execution feature for environment discovery.\n- [SAFE]: The skill incorporates adversarial filtering (Phase 3) that uses a fresh-context verifier to independently check the validity and grounding of all generated ideas before presenting them to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 09:15 PM
Security Audit — agent-trust-hub — ce-ideate