executing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and execute instructions from a 'plan file', which is an inherent indirect prompt injection surface. The risk is mitigated by explicit instructions to 'Review critically' and 'Raise concerns' with the user before starting implementation.
  • Ingestion points: Reads plan files during Step 1 (SKILL.md).
  • Boundary markers: The skill instructs the agent to announce usage and stop for clarification if instructions are unclear.
  • Capability inventory: The skill utilizes file system writing (TodoWrite) and git workspace management via sub-skills.
  • Sanitization: Relies on agent-side critical review rather than automated sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — executing-plans