intent-plan
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines a structured plan format that requires the inclusion of 'E2E Gates' containing shell commands. The provided examples include network operations (
curl), database queries (psql), and build tools (pnpm). These scripts are intended for execution by the agent platform (via/swarm run), which represents a capability to execute arbitrary commands defined in the generated plan. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external project definitions from
INTENT.mdto generate the execution plan. This presents a vulnerability surface where a maliciously crafted intent file could influence the agent to generate harmful shell commands in the resultingplan.mdfile. - Ingestion points: The agent reads content from
INTENT.mdlocated in the workspace. - Boundary markers: The instructions do not mandate the use of delimiters or 'ignore embedded instructions' warnings when the agent processes the intent data.
- Capability inventory: The skill possesses file-writing capabilities (
plan.md,TASK.yaml) and generates shell scripts intended for runtime execution. - Sanitization: The workflow does not specify any sanitization or validation steps for content extracted from
INTENT.mdbefore it is interpolated into the executable plan. - [DYNAMIC_EXECUTION]: The core functionality involves generating a
plan.mdfile which containsbashscript blocks constructed at runtime. While these follow specific testing templates, the logic within the scripts is dynamically generated based on the agent's interpretation of the input intent, qualifying as dynamic script generation.
Audit Metadata