plan-brief
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a development workflow for long-horizon planning and review. It includes safety-oriented constraints, specifically directing the agent to reference secret locations without copying actual credentials and requiring authorization gates for destructive or irreversible operations.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project files and third-party reports to create development plans. 1. Ingestion points: Reads project rules, README, source code modules, and executor reports (SKILL.md). 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in these files. 3. Capability inventory: The skill performs file system reads and writes plans, reports, and reviews to the project's documentation directory. 4. Sanitization: No explicit sanitization or escaping of ingested file content is required.
Audit Metadata