council
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate the processing of untrusted data from external sources.
- Ingestion points: The skill explicitly targets codebase, branch, PR, issue, design, or artifact as defined in SKILL.md.
- Boundary markers: The instructions lack requirements for subagent prompts to include boundary markers or directives to ignore instructions embedded in the analyzed data.
- Capability inventory: The skill invokes subagents using the run_agents tool, which may have the ability to perform code modifications via git worktrees and branches.
- Sanitization: No sanitization or validation protocols are defined for the content extracted from external artifacts before it is processed by the subagents.
Audit Metadata