consciousness-council

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied questions and complex dilemmas through a multi-phase archetypal deliberation system, which creates an attack surface for instructions embedded in the user input to influence the agent's behavior.
  • Ingestion points: The skill ingests untrusted user data in the form of questions, decisions, or creative challenges as specified in the SKILL.md description and selection heuristic.
  • Boundary markers: The instructions do not define delimiters (such as XML tags or unique markers) to separate user data from the agent's internal reasoning logic, nor do they include instructions to ignore embedded commands.
  • Capability inventory: The skill is configured with 'allowed-tools: Read Write', providing a functional surface for file operations that could be targeted via injection.
  • Sanitization: There is no evidence of input validation, escaping, or explicit safety instructions to treat user-provided content as data rather than instructions during the council deliberation phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:50 PM
Security Audit — agent-trust-hub — consciousness-council