project-planning

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it is designed to ingest and process potentially untrusted external inputs—such as requirement documents, technical designs, and existing project code—to generate planning artifacts that direct subsequent agent tasks.- [PROMPT_INJECTION]: Mandatory Evidence Chain for Indirect Prompt Injection Analysis:
  • Ingestion points: The skill reads external data including requirements documents, technical design specifications, and project-specific code or configuration files (documented in the 'Working Method' and 'Completeness Review' sections of SKILL.md).
  • Boundary markers: The instructions specify using only 'confirmed' documents and verifying content against 'project facts' to mitigate accidental adoption of unverified instructions.
  • Capability inventory: The skill possesses the capability to write planning files to the local filesystem (workplace/<version>/implementation-planning/) and orchestrate multi-agent workflows by spawning subagents for verification.
  • Sanitization: A structured completeness review process is implemented using two subagents to identify omissions; however, the instructions explicitly require the primary agent to discard any subagent suggestions that lack 'upstream evidence' or confirmed project facts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 06:22 AM
Security Audit — agent-trust-hub — project-planning