project-planning

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform non-mutating discovery commands and repository inspection. Instructions explicitly restrict these commands to read-only operations to establish planning context without modifying application code or infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the WebFetch tool to retrieve external documentation, architecture details, or other web-based resources needed to clarify project requirements and outcome measures.
  • [PROMPT_INJECTION]: The skill processes untrusted input from user requests and external documentation during its 'Establish the Planning Context' phase. While this presents an indirect prompt injection surface, the skill includes explicit boundary markers and instructions to avoid implementation actions, limiting the potential impact of adversarial content embedded in project requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 06:16 PM
Security Audit — agent-trust-hub — project-planning