counsel
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from a user-provided topic and the content of "relevant files" read during the investigation phase.
- Ingestion points: The parameter in ke:recall and the content of files accessed via "read relevant files" as described in the Workflow section of SKILL.md.
- Boundary markers: Absent. There are no instructions or delimiters (such as XML tags or "ignore instructions" headers) defined for the sub-sessions when processing external data.
- Capability inventory: The expert sub-sessions have the capability to perform file reads, memory retrieval (ke:recall), and generate actionable reports that influence the final synthesis.
- Sanitization: Absent. The skill does not specify any validation, escaping, or filtering on the content of the files or the topic string before presenting them to the expert models.
Audit Metadata