council
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by ingesting untrusted user input and passing it to multiple sub-agents via the
Agenttool call mechanism.\n - Ingestion points: The skill ingests the user's decision dilemma and specific constraints in Step 1 of the facilitation procedure defined in
SKILL.md.\n - Boundary markers: While the skill includes a procedure to restate and confirm the context with the user, there are no technical delimiters (such as structured data wrappers or explicit 'ignore embedded instructions' prompts) when the dilemma is passed to the sub-agents in Step 3 and Step 4.\n
- Capability inventory: The skill possesses the capability to read local files (
references/*.md,assets/*.md) and to invoke other agent definitions located at.claude/agents/using theAgenttool.\n - Sanitization: There is no evidence of input validation, escaping, or filtering of the user's dilemma before it is used to generate prompts for the archetype sub-agents.
Audit Metadata