consult-resume

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts (e.g., discover-projects.sh, engagement-status.sh) and Python scripts (e.g., deliverable-graph.py, generate-engagement-readme.py) from the plugin's root directory to handle project discovery, status reporting, and artifact generation.
  • [COMMAND_EXECUTION]: It orchestrates complex workflows by delegating tasks to other specialized skills within the cogni-consult ecosystem, such as consult-scope, consult-personas, and consult-design-thinking.
  • [COMMAND_EXECUTION]: The skill invokes specialized agents, such as the consult-dashboard-refresher and consult-framework-adherence-reviewer, to provide enhanced views and structural analysis of project deliverables.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill ingests data from local project files (e.g., field.json, assumptions.json) and script outputs to drive its logic. While the skill has significant capabilities including shell execution and tool delegation, the instructions do not explicitly detail boundary markers or sanitization logic for the data ingested from these project sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — consult-resume