writing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external specifications and requirements to generate detailed implementation plans. This creates a surface where malicious instructions embedded in a specification could be reflected in the resulting plan, code, or shell commands.
- Ingestion points: Processes external specs or requirements as primary input for plan generation.
- Boundary markers: The skill instructions do not define specific delimiters or instructions to ignore potential injections within the input specification.
- Capability inventory: The skill generates executable content including code blocks and shell commands (e.g.,
pytest,git) for the agent to follow. - Sanitization: No sanitization, validation, or escaping of the input specification content is specified.
Audit Metadata