review-plan
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is composed of purely instructional text intended to guide the model in reviewing project plans. It contains no executable code, external network requests, or file system operations.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface by processing external data from the 'attached or in-context plan' (Ingestion point). There are no specific boundary markers or sanitization procedures mentioned. However, the capability inventory is extremely limited: the frontmatter contains 'disable-model-invocation: true', and the instructions explicitly state 'never create files', which prevents the agent from performing automated actions based on potentially malicious plan content.
Audit Metadata