review
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface where the content of the artifact being reviewed is interpolated directly into prompts for the reviewing models.
- Ingestion points: Files and directory contents are read via Phase 1 based on user-supplied paths in the
$ARGUMENTSvariable. - Boundary markers: The artifact content is placed inside a markdown structure under headers like
## What you are reviewing, but lacks clear delimiters or instructions to ignore embedded commands within the artifact. - Capability inventory: The skill uses the
Bashtool to invokeconsult-llm, along withRead,Write,Grep, andGlobfor filesystem access. - Sanitization: There is no explicit sanitization or escaping of the artifact content before it is processed by the LLMs.
- [COMMAND_EXECUTION]: Employs dynamic context injection through the
!consult-llm modelscommand. This executes at skill load time to discover and display available model identifiers in the current environment. - [COMMAND_EXECUTION]: Executes the
consult-llmCLI tool via Bash to handle multi-model querying and thread management. The skill explicitly requires this tool to be pre-loaded as a dependency. - [SAFE]: The skill's core functionality involves reading local files and transmitting their content to external LLM services. This behavior is consistent with the stated purpose of performing intellectual debates and critiques on project artifacts.
Audit Metadata