llm-council
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script
python .claude/scripts/code_graphto perform architectural analysis and blast-radius tracing. While this is an internal project tool, it involves executing script-based commands within the repository environment. - [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection due to its automated ingestion of external project documentation to frame decision-support tasks.
- Ingestion points: Processes content from
CLAUDE.md,docs/project-config.json,docs/project-reference/*,docs/specs/*, and user-referenced files. - Boundary markers: The workflow uses structured advisor and reviewer templates to guide the AI's persona and reasoning, though these serve as organizational delimiters rather than security boundaries against malicious documentation content.
- Capability inventory: The agent is authorized to spawn sub-agents (
spawn_agent), execute local Python scripts, and write report artifacts to theplans/reports/directory. - Sanitization: No explicit sanitization, filtering, or validation is performed on the text ingested from the project files before it is interpolated into agent prompts.
Audit Metadata