skills/buiducnhat/cobrew/execute-plan/Gen Agent Trust Hub

execute-plan

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is instructed to run shell commands for verification, linting, type-checking, and building as part of the plan execution process. Specifically, it executes 'phase-specific verification commands' directly from the content of the plan files (e.g., SUMMARY.md), which could lead to arbitrary command execution if the plan content is malicious.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon instructions contained in external markdown files located in the project's directory. This creates a surface for indirect injection where malicious instructions or commands could be embedded in a plan file to manipulate the agent's behavior or the local environment.
  • Ingestion points: The skill reads docs/.plans/**/SUMMARY.md and related phase files to determine its implementation tasks and verification steps.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or sanitize embedded instructions within the plan data.
  • Capability inventory: The skill possesses significant capabilities including shell command execution, file writing, and directory manipulation (archiving folders).
  • Sanitization: No sanitization or validation of the commands or instructions found within the plan files is performed before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:46 PM
Security Audit — agent-trust-hub — execute-plan