council
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user questions and codebase snippets to facilitate decision-making.\n
- Ingestion points: User-provided decision questions and repository context files (SKILL.md Step 2).\n
- Boundary markers: The skill employs a mitigation strategy by instructing the agent to launch fresh subagents with limited context and no conversation history (SKILL.md Step 4).\n
- Capability inventory: The skill supports updating external platforms like GitHub or Linear and using session-based persistence tools (Persistence Rule).\n
- Sanitization: The architecture uses subagent isolation as a structural boundary to limit the influence of potentially malicious instructions in the input data.
Audit Metadata