advisor
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by reading repository content which is then used to influence the agent's reasoning.
- Ingestion points: Repository content is read using the Read, Grep, and Glob tools as specified in the Agent calls and claude CLI instructions in SKILL.md.
- Boundary markers: The skill instructs the agent to prepare the consult in a file and feed it over stdin to prevent shell interpolation, and defines an 'advice contract' to constrain the advisor's output.
- Capability inventory: The skill utilizes Read, Grep, and Glob capabilities in its advisor channels, while explicitly maintaining that advisor models should be read-only and not allowed to execute code or edit files.
- Sanitization: No automated sanitization is described, but the instructions require the user or agent to manually exclude secrets and credentials before consultation.
- [COMMAND_EXECUTION]: The skill provides instructions for executing the claude CLI to facilitate remote consultations.
- Evidence: SKILL.md contains a bash script using the claude command with several flags (--safe-mode, --permission-mode plan, --tools 'Read,Grep,Glob').
- Context: This command execution is intended for consultation purposes and includes security best practices such as unsetting the ANTHROPIC_API_KEY environment variable before execution to prevent unintended credential usage or leakage. The claude tool is provided by a known, trusted vendor.
Audit Metadata