start-plan
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a structured 'Perceive-Reason-Act' framework focused on project management and planning. It explicitly restricts the agent from writing code or modifying files during the planning phase.
- [PROMPT_INJECTION]: The skill processes project files and dependencies to gain context, which creates a theoretical surface for indirect prompt injection from untrusted codebase content. However, given the skill's primary function is analysis and it lacks autonomous execution capabilities (no file writes or shell execution), the risk is negligible.
- [DATA_EXFILTRATION]: While the skill performs reconnaissance on the local file system to identify project patterns and dependencies (e.g., mapping files via
grep_searchandglob), there are no instructions to transmit this data to external domains or non-whitelisted sources.
Audit Metadata