chief-of-staff
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it orchestrates and synthesizes data from untrusted user inputs ('founder questions') and up to 28 different sub-agent advisor skills. Ingestion points: founder questions provided in the interaction session and advisor responses collected across the routing matrix. Boundary markers: uses markdown headers and a specific invocation syntax ([INVOKE:role|question]) to distinguish between different agent contexts. Capability inventory: file system access for maintaining a persistent decision log at ~/.claude/decision-log.md. Sanitization: no explicit sanitization or filtering of external content before synthesis is documented.
- [SAFE]: The decision logging functionality is limited to the agent's local configuration directory and is used strictly for intended persistence and review tasks. The skill demonstrates clear management of agent autonomy through its critical loop prevention protocols and established decision complexity scoring.
Audit Metadata