council

Fail

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: HIGHDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to access sensitive file paths including auth and security directories on the local filesystem when the domain is classified as 'security'. These locations typically store sensitive credentials, SSH keys, or environment secrets.
  • [DATA_EXFILTRATION]: The skill includes functionality to send summarized data to external messaging platforms such as Telegram, Discord, and Slack via the hermes MCP server, providing a potential pathway for exfiltrating gathered information.
  • [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because it ingests untrusted data from multiple sources (GitHub PRs, issues, commits, and web search results from Brave Search and Tavily). It lacks mandatory sanitization, escaping, or boundary markers (e.g., delimiters) to prevent malicious instructions embedded in that data from hijacking the agent's logic during the advisor or synthesis phases.
  • [COMMAND_EXECUTION]: The skill automatically generates and executes system tasks using the TaskCreate tool based on recommendations from the 'Executor' advisor. Since these recommendations are derived from untrusted external data, an attacker could influence the agent to perform unauthorized actions.
  • [COMMAND_EXECUTION]: The agent is instructed to write HTML files directly to the local filesystem at ~/.claude/council-reports/. This involves assembling content from untrusted external sources into an executable format (HTML) that is then stored on the user's machine.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — council