skills/buiducnhat/cobrew/write-plan/Gen Agent Trust Hub

write-plan

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data which can lead to indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: The skill reads docs/SUMMARY.md, project-specific documentation, and source code files during the 'Contextualize' phase (Step 1).
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the ingested files.
  • Capability inventory: The skill has the capability to write implementation plans to docs/.plans/ and generate visualization files using an external visualize tool.
  • Sanitization: There is no evidence of sanitization or filtering of external content before it is processed or included in plan artifacts.
  • [EXTERNAL_DOWNLOADS]: Step 5 of the workflow ('Research') permits the agent to consult external references if the environment provides that capability. While no malicious URLs are provided, this allows for network activity that should be monitored based on the tools available to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:47 PM
Security Audit — agent-trust-hub — write-plan