ccdawn-planning

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for read-only analysis and document generation. It explicitly restricts its own actions to analytical tasks and prohibits the modification of business code.
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified in 'plan-document-reviewer-prompt.md'. 1. Ingestion points: The subagent reads plan and specification files via '[PLAN_FILE_PATH]' and '[SPEC_FILE_PATH]'. 2. Boundary markers: Absent. 3. Capability inventory: Read-only analysis and document generation as defined in 'SKILL.md'; no code execution, file modification, or network capabilities. 4. Sanitization: Absent. The risk is assessed as safe due to the skill's strictly analytical scope and lack of exploitable actions.
  • [EXTERNAL_DOWNLOADS]: No external network operations or downloads from untrusted sources were detected. All components and referenced skills are internal to the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:31 AM
Security Audit — agent-trust-hub — ccdawn-planning