consult-publish

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes external content without sufficient isolation.
  • Ingestion points: Content is read from deliverable markdown files and a project assumptions registry (assumptions.json) (File: SKILL.md).
  • Boundary markers: The skill lacks instructions for the agent to use delimiters or ignore instructions that may be embedded within the project data.
  • Capability inventory: The skill has access to powerful capabilities including Bash execution, project file Editing, and the ability to call other Skills (File: SKILL.md).
  • Sanitization: There are no explicit requirements for validating or escaping content from the deliverables before it is used in brief generation.
  • [SAFE]: The skill utilizes a vendor-owned resource cogni-copywriting:copywriter for optional text enhancement, which is a legitimate use of the product ecosystem and aligns with the author's identity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — consult-publish