consult-scope
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell and Python scripts (
discover-projects.sh,deliverable-graph.py) located within the environment's plugin root directory. These scripts are used for engagement discovery and managing deliverable dependencies. - [PROMPT_INJECTION]: Instructions were reviewed for adversarial patterns, role-play injections, or attempts to bypass safety filters. The instructions are focused on guiding a structured consulting methodology and do not contain override markers.
- [DATA_EXFILTRATION]: The skill manages project-specific JSON and Markdown files. It explicitly mandates that research for scoping dimensions must be routed through a bound knowledge base rather than public web searches, which acts as a safeguard against data leakage.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user input to populate dimension notes and research seeds. While this represents a data ingestion surface, the processed content is stored in project artifacts and used by other internal consulting skills, with no identified path to escalate privileges or execute unauthorized code.
Audit Metadata