agents-consilium
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted repository content, creating a surface for indirect prompt injection where malicious files could attempt to subvert sub-agents. 1. Ingestion points: Repository files are rendered into templates in
scripts/lib/discovery-pass.shandscripts/lib/backend_run.sh. 2. Boundary markers: Present. The skill uses trusted delimiters and a contract recap inprompts/review-recap.txtto explicitly instruct sub-agents to ignore embedded instructions. 3. Capability inventory: The skill manages subprocesses (CLIs) with shell and file system access; sub-agents are restricted by native sandboxes in review mode. 4. Sanitization: Code content is CDATA-wrapped with terminator escaping inscripts/lib/common.sh.\n- [COMMAND_EXECUTION]: The skill launches external agent CLIs (Claude, Codex, Grok, etc.) using subprocesses. It enforces security by applying restrictive flags in review mode, such as--sandbox read-onlyand--permission-mode dontAsk. It also uses a high-privilegedelegatemode for implementation tasks, which is the core documented purpose of the skill.\n- [DATA_EXFILTRATION]: Network operations are performed for quota checks and sub-agent communication. Safeguards inscripts/lib/steer/adapters/opencode.pyandscripts/lib/steer/util.pystrictly restrict communication to the local loopback interface viais_loopback_url. Furthermore,scripts/lib/redact_stream.pyensures that credentials are removed from diagnostic logs before they are stored or displayed.
Audit Metadata