council

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate the processing of untrusted data from external sources.
  • Ingestion points: The skill explicitly targets codebase, branch, PR, issue, design, or artifact as defined in SKILL.md.
  • Boundary markers: The instructions lack requirements for subagent prompts to include boundary markers or directives to ignore instructions embedded in the analyzed data.
  • Capability inventory: The skill invokes subagents using the run_agents tool, which may have the ability to perform code modifications via git worktrees and branches.
  • Sanitization: No sanitization or validation protocols are defined for the content extracted from external artifacts before it is processed by the subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:09 PM
Security Audit — agent-trust-hub — council