deep-council
Pass
Audited by Gen Agent Trust Hub on Mar 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) where outputs from external model bridges are processed by a central 'Debate Coordinator' agent.\n- Ingestion points: Bridge reports from Claude, Gemini, Codex, and OpenCode are ingested into the synthesis phase.\n- Boundary markers: Findings are grouped under headers but lack explicit delimiters or 'ignore embedded instructions' warnings.\n- Capability inventory: The skill uses Task, Bash, Read, and Write tools, allowing significant system interaction.\n- Sanitization: No sanitization of the bridge outputs is performed before interpolation into the debate prompt.\n- [COMMAND_EXECUTION]: The skill executes several system commands for environment discovery and management: 'codex models list', 'opencode auth list', 'which gemini', and 'qmd collection add'.\n- [EXTERNAL_DOWNLOADS]: The documentation suggests manually installing missing dependencies from 'https://github.com/mikeng-io/agent-skills'. As this is the vendor's repository, it is documented as a standard setup operation.
Audit Metadata