create-plan
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection where malicious instructions embedded in project files could influence the agent behavior.
- Ingestion points: The skill reads
specs/CONSTITUTION.md,SPEC.mdfiles, and explores the wider codebase to identify implementation patterns. - Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions found within the files being processed.
- Capability inventory: The skill possesses file-write permissions for creating
PLAN.mdfiles and can spawn subagents using the Agent tool for codebase exploration. - Sanitization: No explicit sanitization or validation of the ingested file content is performed prior to processing.
Audit Metadata