executing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and execute instructions from a 'plan file', which is an inherent indirect prompt injection surface. The risk is mitigated by explicit instructions to 'Review critically' and 'Raise concerns' with the user before starting implementation.
- Ingestion points: Reads plan files during Step 1 (SKILL.md).
- Boundary markers: The skill instructs the agent to announce usage and stop for clarification if instructions are unclear.
- Capability inventory: The skill utilizes file system writing (TodoWrite) and git workspace management via sub-skills.
- Sanitization: Relies on agent-side critical review rather than automated sanitization.
Audit Metadata