mckinsey-consultant

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Indirect Prompt Injection (MEDIUM): The skill executes 15-30 web searches to populate its analysis framework and slide content. Evidence: Step 3 and Step 6 of the workflow.md file describe extensive data collection from the open web. Ingestion points: Results from web_search enter the context to build the Hypothesis Tree and Dummy Pages. Boundary markers: No delimiters or instructions to ignore embedded commands are present in the reference files. Capability inventory: The agent can perform web searches, read local files, and call the external mckinsey-ppt-v4 tool to generate documents. Sanitization: No sanitization process is described for data retrieved from external sources before it influences the agent's reasoning.
  • External Dependency (LOW): The skill depends on mckinsey-ppt-v4 for its core output capability. This is an unverified external dependency that lacks integrity checks or specific source verification in the provided documentation. Evidence: README.md and design-specs.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 09:02 AM