00-andruia-consultant-v2

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified during the analysis of the skill's instructions, metadata, or provenance documentation.
  • [PROMPT_INJECTION]: The skill analyzes untrusted local project files to provide technical consultations, presenting a surface for indirect prompt injection. This behavior is consistent with the skill's primary purpose.
  • Ingestion points: Project files such as package.json and the src directory (SKILL.md).
  • Boundary markers: Absent; there are no specific instructions to treat file content as untrusted or separate it from the system instructions.
  • Capability inventory: The skill utilizes codex-cli, claude-code, cursor, gemini-cli, and opencode, and generates local markdown files (tareas.md, plan_implementacion.md).
  • Sanitization: Absent; the instructions do not specify any validation or sanitization of the scanned file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 09:22 PM
Security Audit — agent-trust-hub — 00-andruia-consultant-v2