agents-consilium

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted repository content, creating a surface for indirect prompt injection where malicious files could attempt to subvert sub-agents. 1. Ingestion points: Repository files are rendered into templates in scripts/lib/discovery-pass.sh and scripts/lib/backend_run.sh. 2. Boundary markers: Present. The skill uses trusted delimiters and a contract recap in prompts/review-recap.txt to explicitly instruct sub-agents to ignore embedded instructions. 3. Capability inventory: The skill manages subprocesses (CLIs) with shell and file system access; sub-agents are restricted by native sandboxes in review mode. 4. Sanitization: Code content is CDATA-wrapped with terminator escaping in scripts/lib/common.sh.\n- [COMMAND_EXECUTION]: The skill launches external agent CLIs (Claude, Codex, Grok, etc.) using subprocesses. It enforces security by applying restrictive flags in review mode, such as --sandbox read-only and --permission-mode dontAsk. It also uses a high-privilege delegate mode for implementation tasks, which is the core documented purpose of the skill.\n- [DATA_EXFILTRATION]: Network operations are performed for quota checks and sub-agent communication. Safeguards in scripts/lib/steer/adapters/opencode.py and scripts/lib/steer/util.py strictly restrict communication to the local loopback interface via is_loopback_url. Furthermore, scripts/lib/redact_stream.py ensures that credentials are removed from diagnostic logs before they are stored or displayed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:09 AM
Security Audit — agent-trust-hub — agents-consilium