council
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted codebase data to drive the spawning of multiple task agents and execute user requests. There is a risk that malicious instructions embedded in the codebase could influence these agents.\n
- Ingestion points: codebase files and architecture overview (SKILL.md)\n
- Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions embedded in the codebase data.\n
- Capability inventory: Reading codebase content and spawning up to 10 task agents (SKILL.md).\n
- Sanitization: None identified; the skill processes codebase information directly without validation or filtering.
Audit Metadata