plan-before-code
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional documentation and procedural templates. No executable scripts, tool definitions, or subprocess calls are present.
- [INDIRECT_PROMPT_INJECTION]: The skill defines templates that process user-supplied descriptions. While this is an entry point for external data, the skill lacks capabilities to act upon malicious instructions. (Ingestion points: User input fields in SKILL.md; Boundary markers: Absent; Capability inventory: None; Sanitization: N/A).
Audit Metadata