council

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Attack Surface]: The skill is designed to ingest and analyze external targets, including file paths and repository content provided via user arguments in SKILL.md. This represents an ingestion point for potentially untrusted data. The skill implements boundary markers by using isolated sub-sessions for each reviewer lens with context_depth="none", preventing cross-contamination of context. The capability inventory includes the delegate tool for sub-session orchestration and foundation:explorer for repository mapping. While it relays verbatim outputs during the debate phase, the use of isolated sessions and neutral digests acts as a sanitization measure to reduce the risk of the agent following malicious instructions embedded in the target data.
  • [Automated Tool Orchestration]: The skill utilizes a delegation pattern to load and execute sub-skills such as intent-keeper and tester-breaker. While these are internal components of the bundle, the interaction involves passing data between agents. The skill includes logic to handle failures in loading these components gracefully, ensuring the orchestration remains robust and the execution environment is monitored.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:27 AM
Security Audit — agent-trust-hub — council