llm-council

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script python .claude/scripts/code_graph to perform architectural analysis and blast-radius tracing. While this is an internal project tool, it involves executing script-based commands within the repository environment.
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection due to its automated ingestion of external project documentation to frame decision-support tasks.
  • Ingestion points: Processes content from CLAUDE.md, docs/project-config.json, docs/project-reference/*, docs/specs/*, and user-referenced files.
  • Boundary markers: The workflow uses structured advisor and reviewer templates to guide the AI's persona and reasoning, though these serve as organizational delimiters rather than security boundaries against malicious documentation content.
  • Capability inventory: The agent is authorized to spawn sub-agents (spawn_agent), execute local Python scripts, and write report artifacts to the plans/reports/ directory.
  • Sanitization: No explicit sanitization, filtering, or validation is performed on the text ingested from the project files before it is interpolated into agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — llm-council