planning-work-item-tasks

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed with a high degree of process isolation and structural integrity. It uses a sequence of specialized subagents and validators to ensure that output artifacts conform to strict safety and quality standards before being finalized.
  • [EXTERNAL_DOWNLOADS]: The skill includes references to external documentation and best-practice guides from well-known technology vendors and organizations (such as GitHub, Atlassian, and Wikipedia). These URLs are used solely for information enrichment and do not involve the download or execution of remote scripts.
  • [PROMPT_INJECTION]: While the skill processes untrusted input from external work-item snapshots, it explicitly mitigates indirect prompt injection risks by instructing the agent to treat snapshot content as data rather than instructions. This is further reinforced by the use of static templates and independent validation stages that check for structural anomalies.
  • [COMMAND_EXECUTION]: Mutation capabilities are strictly bounded. The skill is authorized only to read and write Markdown documentation within the local docs/ directory and is explicitly prohibited from modifying source code, repository configurations, or external platform states.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:38 AM
Security Audit — agent-trust-hub — planning-work-item-tasks