execute-plan
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is instructed to run shell commands for verification, linting, type-checking, and building as part of the plan execution process. Specifically, it executes 'phase-specific verification commands' directly from the content of the plan files (e.g.,
SUMMARY.md), which could lead to arbitrary command execution if the plan content is malicious. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon instructions contained in external markdown files located in the project's directory. This creates a surface for indirect injection where malicious instructions or commands could be embedded in a plan file to manipulate the agent's behavior or the local environment.
- Ingestion points: The skill reads
docs/.plans/**/SUMMARY.mdand related phase files to determine its implementation tasks and verification steps. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or sanitize embedded instructions within the plan data.
- Capability inventory: The skill possesses significant capabilities including shell command execution, file writing, and directory manipulation (archiving folders).
- Sanitization: No sanitization or validation of the commands or instructions found within the plan files is performed before execution.
Audit Metadata