writing-plans
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a standard software engineering workflow, promoting TDD and incremental commits. It utilizes common development tools like
pytestandgitfor legitimate purposes within the implementation plans it generates. - [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes external specifications into implementation plans. However, this is inherent to its primary purpose, and the skill includes mitigation steps such as a structured review process for generated plans. * Ingestion points: User-provided specifications or requirements. * Boundary markers: Absent for inputs; output uses structured Markdown formatting. * Capability inventory: Generates content containing shell commands and Python code for potential execution. * Sanitization: Instructions do not provide specific sanitization or validation rules for the input content.
Audit Metadata