llm-council

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied queries through a three-phase deliberation process involving multiple LLMs, creating an injection surface.\n
  • Ingestion points: User input is accepted as a command-line argument for the run command in scripts/council.js.\n
  • Boundary markers: The input is interpolated directly into system and user prompts without delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: The script performs network operations (LLM API calls), file writes (session transcripts), and database updates via a local wiki store.\n
  • Sanitization: No validation or escaping is applied to the user query before it is sent to the council models.\n- [DYNAMIC_EXECUTION]: The script dynamically loads a local database module to support its wiki integration feature.\n
  • Evidence: In scripts/council.js, the persistToWiki function uses require(distPath) where distPath is a path calculated at runtime relative to the script location.\n- [EXTERNAL_DOWNLOADS]: The skill makes network requests to external AI service providers to conduct the deliberation phases.\n
  • Evidence: It connects to official API endpoints for Anthropic, OpenAI, OpenRouter, and Fireworks to generate model responses and rankings.\n- [DATA_EXFILTRATION]: The skill supports a custom API base URL which, if misconfigured, could lead to the transmission of API keys to an untrusted endpoint.\n
  • Evidence: The custom provider configuration in scripts/council.js uses the LLM_COUNCIL_BASE_URL environment variable to define the target for requests containing the LLM_COUNCIL_API_KEY bearer token.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:20 AM
Security Audit — agent-trust-hub — llm-council