2-plan
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary logic depends on reading and interpreting the content of documentation files located in the
docs/directory, such aslearner-profile.mdandscope.md. These files are intended to be user-influenced or generated during the workflow. The agent is explicitly instructed to treat these files as "the truth," which allows for a potential attack where malicious instructions within these documents could override the agent's operational guidelines. - Ingestion points: The routing and decision-making logic in
SKILL.mdreadsdocs/learner-profile.md,docs/scope.md,docs/prd.md,docs/spec.md, anddocs/checklist.mdat the start of each execution. - Boundary markers: The skill uses YAML frontmatter status fields for routing, but does not implement delimiters or specific "ignore" instructions for the body content of the ingested files.
- Capability inventory: The agent has permissions to read and write markdown files in the project directory and influence subsequent steps in the curriculum (
1-start,3-build). - Sanitization: The skill lacks explicit sanitization or validation logic for the content of the documents it processes as its source of state.
Audit Metadata