ce-update

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection (the !command syntax) to execute local shell utilities like echo, grep, basename, and dirname. These are used to parse the ${CLAUDE_SKILL_DIR} environment variable and determine the current installation path and version.
  • [EXTERNAL_DOWNLOADS]: The skill uses the GitHub CLI (gh api) to retrieve the plugin.json file from the author's official repository (EveryInc/compound-engineering-plugin). This fetch is used solely to obtain the latest version string for comparison purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:00 AM