council

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted codebase data to drive the spawning of multiple task agents and execute user requests. There is a risk that malicious instructions embedded in the codebase could influence these agents.\n
  • Ingestion points: codebase files and architecture overview (SKILL.md)\n
  • Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions embedded in the codebase data.\n
  • Capability inventory: Reading codebase content and spawning up to 10 task agents (SKILL.md).\n
  • Sanitization: None identified; the skill processes codebase information directly without validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 10:29 PM
Security Audit — agent-trust-hub — council