consultancy-practices

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions and schema reveals no malicious behavior or safety violations. The skill is limited to professional advisory roles and quality assessments within a defined project scope.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a standard functional surface for processing external project data. 1. Ingestion points: The skill accesses the client-project directory via the Assess Codebase task mentioned in SKILL.md. 2. Boundary markers: Explicit delimiters for external content are not defined in the skill instructions. 3. Capability inventory: The skill is restricted to analysis, risk assessment, and fleet coordination tasks. 4. Sanitization: Content processing relies on the underlying agent platform safety mechanisms. This surface is considered safe as it is inherent to the skill's primary diagnostic purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:15 PM
Security Audit — agent-trust-hub — consultancy-practices