create-plan

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for indirect prompt injection where malicious instructions embedded in project files could influence the agent behavior.
  • Ingestion points: The skill reads specs/CONSTITUTION.md, SPEC.md files, and explores the wider codebase to identify implementation patterns.
  • Boundary markers: The instructions do not define clear delimiters or include warnings to ignore instructions found within the files being processed.
  • Capability inventory: The skill possesses file-write permissions for creating PLAN.md files and can spawn subagents using the Agent tool for codebase exploration.
  • Sanitization: No explicit sanitization or validation of the ingested file content is performed prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 10:14 AM
Security Audit — agent-trust-hub — create-plan