writing-plans
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill acts as a processing layer for external requirements, which introduces a surface for indirect prompt injection where malicious instructions in a specification could influence the agent's output.
- Ingestion points: User-provided specifications or requirements as described in the overview of SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or instructions to isolate the untrusted specification data from the plan generation logic.
- Capability inventory: The skill provides instructions for the agent to generate file paths in the 'docs/plans/' directory and shell commands for 'git' and 'pytest'.
- Sanitization: There are no explicit sanitization or validation steps for the content of the input specifications mentioned in the skill.
Audit Metadata