capacity-planner
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON data (team rosters and commitment lists) which acts as a potential surface for indirect prompt injection where malicious instructions could influence the agent's summary of calculations.
- Ingestion points: The scripts capacity_model.py, commitment_gap.py, and scenario_compare.py ingest data from local JSON files specified by the user via the --input argument.
- Boundary markers: No explicit delimiters or instructions are used to separate user-provided data from the agent's reasoning process when reporting results.
- Capability inventory: The Python scripts are limited to mathematical processing and standard output; they do not perform network operations, file writes, or command execution beyond their own invocation.
- Sanitization: Input data is parsed as JSON and validated for structure, but individual string fields like member names or project descriptions are not sanitized for potential natural language instructions.
Audit Metadata