00-andruia-consultant-v2
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified during the analysis of the skill's instructions, metadata, or provenance documentation.
- [PROMPT_INJECTION]: The skill analyzes untrusted local project files to provide technical consultations, presenting a surface for indirect prompt injection. This behavior is consistent with the skill's primary purpose.
- Ingestion points: Project files such as
package.jsonand thesrcdirectory (SKILL.md). - Boundary markers: Absent; there are no specific instructions to treat file content as untrusted or separate it from the system instructions.
- Capability inventory: The skill utilizes
codex-cli,claude-code,cursor,gemini-cli, andopencode, and generates local markdown files (tareas.md,plan_implementacion.md). - Sanitization: Absent; the instructions do not specify any validation or sanitization of the scanned file content.
Audit Metadata