skills/agent-sh/agentsys/consult/Gen Agent Trust Hub

consult

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external AI CLI tools including claude, gemini, codex, opencode, and copilot. These executions are parameterized with user-supplied flags that are filtered for shell metacharacters.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to download and execute ACP adapters for Claude and Codex. These packages (@anthropic-ai/claude-code-acp and @zed-industries/codex-acp) originate from well-known and reputable organizations.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external AI tool responses and local files via the --context argument, creating a surface for embedded instructions.
  • Ingestion points: Tool outputs (stdout), context files (via Read tool).
  • Boundary markers: None explicitly implemented for tool response interpolation.
  • Capability inventory: Command execution of CLI tools, file writing (temporary question files), and file reading.
  • Sanitization: Implements an extensive regex-based redaction system for API keys (Anthropic, OpenAI, Google, GitHub, AWS) and Authorization headers.
  • [DYNAMIC_EXECUTION]: The skill dynamically builds shell commands from templates and executes a local script (acp/run.js) to handle ACP transport for specific providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:08 AM
Security Audit — agent-trust-hub — consult