consulting-discover

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local script, update-phase.sh, which manages the state of the consulting project. This operation is limited to the skill's own environment and is a standard administrative task.
  • [PROMPT_INJECTION]: The skill processes information from multiple external data sources, including research reports, trend scans, and competitive analysis, to generate a discovery synthesis. While this represents an indirect prompt injection surface, it is the primary intended function of the skill and involves data generated by other tools within the same vendor ecosystem.
  • Ingestion points: Reads files from discover/research/, discover/trends/, discover/competitive/, and interactive input from guided method sessions.
  • Boundary markers: None identified in the instructional text.
  • Capability inventory: The skill has access to Write, Edit, and Bash tools to store the synthesis and update project tasks.
  • Sanitization: No specific sanitization or filtering logic is implemented; the agent is expected to synthesize the content neutrally.
  • [SAFE]: The skill coordinates with other specialized tools (cogni-research, cogni-trends, cogni-portfolio) using the platform's standard dispatch mechanisms. These are recognized resources belonging to the same author and do not constitute an external security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:41 PM
Security Audit — agent-trust-hub — consulting-discover