skills/johnlindquist/claude/council/Gen Agent Trust Hub

council

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install CLI tools from established AI providers, including Google, OpenAI, and Anthropic, via npm and pip.
  • [COMMAND_EXECUTION]: The skill uses shell scripts to perform parallel queries, handle background jobs using the & operator, and manage temporary files for response storage.
  • [INDIRECT_PROMPT_INJECTION]: * Ingestion points: The skill ingests untrusted data from local files (e.g., source code via cat) and uses the output of one AI agent as input for another in debate and synthesis patterns. * Boundary markers: External data is interpolated directly into prompts (e.g., $CODE, $R1_GEMINI) without the use of boundary markers or instructions to ignore embedded commands. * Capability inventory: The skill possesses the capability to read files, execute CLI tools, and write to temporary directories. * Sanitization: There is no evidence of sanitization or validation of the data being passed between the file system and the AI models.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — council