advisory-board

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the open command in Phase 6 to automatically display the generated HTML visualization report in the user's default web browser.
  • [EXTERNAL_DOWNLOADS]: The README provides installation instructions that involve fetching files from the author's public GitHub repository (Backtthefuture/huangshu) via npx, git clone, or curl.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is configured to read from user-defined local directories (e.g., 00-我/) containing personal goals, values, and decision history to personalize the simulation. While the agent has network tool access (WebSearch, WebFetch), no instructions to transmit this data externally were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied business topics which are interpolated into advisor responses. This ingestion point lacks explicit sanitization or strict boundary markers, which is common in advisory skills. The instruction for advisors to maintain their specific "DNA" and the facilitator to keep the discussion on track acts as a functional guardrail against typical injection-based persona drifting.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 02:20 AM