planning-and-task-breakdown

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content for project planning and task decomposition without any executable code or dangerous command patterns.
  • [PROMPT_INJECTION]: The skill defines a workflow for processing external specifications, which represents a potential surface for indirect prompt injection. This is evaluated as safe due to the restricted environment.
  • Ingestion points: External specifications or requirements provided in the agent's context.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: Limited to read-only file system tools (Read, Glob, Grep) as specified in the allowed-tools frontmatter.
  • Sanitization: None specified; however, the output is a plan document intended for human review, which serves as a natural security checkpoint.
  • [SAFE]: The skill references an external repository on GitHub for attribution purposes. As GitHub is a well-known service and no automated downloads or executions are performed, this reference does not pose a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:50 AM
Security Audit — agent-trust-hub — planning-and-task-breakdown