consult-publish
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes external content without sufficient isolation.
- Ingestion points: Content is read from deliverable markdown files and a project assumptions registry (
assumptions.json) (File: SKILL.md). - Boundary markers: The skill lacks instructions for the agent to use delimiters or ignore instructions that may be embedded within the project data.
- Capability inventory: The skill has access to powerful capabilities including
Bashexecution, project fileEditing, and the ability to call otherSkills (File: SKILL.md). - Sanitization: There are no explicit requirements for validating or escaping content from the deliverables before it is used in brief generation.
- [SAFE]: The skill utilizes a vendor-owned resource
cogni-copywriting:copywriterfor optional text enhancement, which is a legitimate use of the product ecosystem and aligns with the author's identity.
Audit Metadata