llm-council
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied queries through a three-phase deliberation process involving multiple LLMs, creating an injection surface.\n
- Ingestion points: User input is accepted as a command-line argument for the
runcommand inscripts/council.js.\n - Boundary markers: The input is interpolated directly into system and user prompts without delimiters or instructions to ignore embedded commands.\n
- Capability inventory: The script performs network operations (LLM API calls), file writes (session transcripts), and database updates via a local wiki store.\n
- Sanitization: No validation or escaping is applied to the user query before it is sent to the council models.\n- [DYNAMIC_EXECUTION]: The script dynamically loads a local database module to support its wiki integration feature.\n
- Evidence: In
scripts/council.js, thepersistToWikifunction usesrequire(distPath)wheredistPathis a path calculated at runtime relative to the script location.\n- [EXTERNAL_DOWNLOADS]: The skill makes network requests to external AI service providers to conduct the deliberation phases.\n - Evidence: It connects to official API endpoints for Anthropic, OpenAI, OpenRouter, and Fireworks to generate model responses and rankings.\n- [DATA_EXFILTRATION]: The skill supports a custom API base URL which, if misconfigured, could lead to the transmission of API keys to an untrusted endpoint.\n
- Evidence: The
customprovider configuration inscripts/council.jsuses theLLM_COUNCIL_BASE_URLenvironment variable to define the target for requests containing theLLM_COUNCIL_API_KEYbearer token.
Audit Metadata