2-plan

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary logic depends on reading and interpreting the content of documentation files located in the docs/ directory, such as learner-profile.md and scope.md. These files are intended to be user-influenced or generated during the workflow. The agent is explicitly instructed to treat these files as "the truth," which allows for a potential attack where malicious instructions within these documents could override the agent's operational guidelines.
  • Ingestion points: The routing and decision-making logic in SKILL.md reads docs/learner-profile.md, docs/scope.md, docs/prd.md, docs/spec.md, and docs/checklist.md at the start of each execution.
  • Boundary markers: The skill uses YAML frontmatter status fields for routing, but does not implement delimiters or specific "ignore" instructions for the body content of the ingested files.
  • Capability inventory: The agent has permissions to read and write markdown files in the project directory and influence subsequent steps in the curriculum (1-start, 3-build).
  • Sanitization: The skill lacks explicit sanitization or validation logic for the content of the documents it processes as its source of state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 04:36 PM
Security Audit — agent-trust-hub — 2-plan