consult-action-fields
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run local scripts such asdiscover-projects.sh,engagement-status.sh, anddeliverable-graph.py. These scripts are part of the plugin's internal directory and are used for project discovery and validation. - [PROMPT_INJECTION]: The skill processes project-specific data which creates an indirect prompt injection surface. Ingestion points:
consult-project.jsonandfield.jsonfiles. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified in the workflow. Capability inventory: Uses theBashtool to execute scripts with interpolated project paths. Sanitization: No explicit validation or sanitization of project-defined slugs or paths is mentioned.
Audit Metadata