everyinc/compound-engineering-plugin ce-sweep
Checked the catalogued skill at ce-sweep.
A set by no findings on this axis
A set by no findings on this axis
A set by no findings on this axis
No issues flagged by the static checks in the scanned files.
5 suppressed by AI triage
The snippet only describes rendering a command string and does not contain any DNS query or data exfiltration logic.
Documentation shows setting a user‑specific /tmp path, a safe example rather than an exploit.
The snippet is documentation that creates a user‑specific temp directory; it does not exploit or expose system files.
The script constructs a curl command to a legitimate OpenAI API endpoint as part of its intended transcription functionality, not malicious exfiltration.
The reference to https:[REDACTED] is a normal, intended outbound call for audio transcription, not suspicious.