home-consult
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill performs its intended consultative functions by reading project-specific configuration and documentation files, with no evidence of malicious command execution or unauthorized data exfiltration.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting local project files (such as src/lib/config/tenant.config.ts, src/app/(public)/page.tsx, and the _docs/ directory) which could be used to host adversarial instructions. Ingestion points: src/lib/config/tenant.config.ts, src/app/(public)/page.tsx, _docs/. Boundary markers: Absent. Capability inventory: Read, Grep, Glob, Agent, WebSearch, WebFetch. Sanitization: Absent.
Audit Metadata