council
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install CLI tools from established AI providers, including Google, OpenAI, and Anthropic, via npm and pip.
- [COMMAND_EXECUTION]: The skill uses shell scripts to perform parallel queries, handle background jobs using the
&operator, and manage temporary files for response storage. - [INDIRECT_PROMPT_INJECTION]: * Ingestion points: The skill ingests untrusted data from local files (e.g., source code via
cat) and uses the output of one AI agent as input for another in debate and synthesis patterns. * Boundary markers: External data is interpolated directly into prompts (e.g.,$CODE,$R1_GEMINI) without the use of boundary markers or instructions to ignore embedded commands. * Capability inventory: The skill possesses the capability to read files, execute CLI tools, and write to temporary directories. * Sanitization: There is no evidence of sanitization or validation of the data being passed between the file system and the AI models.
Audit Metadata