writing-plans

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill acts as a processing layer for external requirements, which introduces a surface for indirect prompt injection where malicious instructions in a specification could influence the agent's output.
  • Ingestion points: User-provided specifications or requirements as described in the overview of SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to isolate the untrusted specification data from the plan generation logic.
  • Capability inventory: The skill provides instructions for the agent to generate file paths in the 'docs/plans/' directory and shell commands for 'git' and 'pytest'.
  • Sanitization: There are no explicit sanitization or validation steps for the content of the input specifications mentioned in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — writing-plans