planning-with-files

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines several automation hooks in the YAML frontmatter that trigger shell commands during the agent session. These include using cat to display file contents in the PreToolUse hook and executing a local validation script check-complete.sh in the Stop hook.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by automatically ingesting the content of filesystem files into the active agent context.
  • Ingestion points: The PreToolUse hook in SKILL.md automatically reads and displays the beginning of the task_plan.md file from the working directory before every Write, Edit, or Bash command.
  • Boundary markers: No boundary markers or delimiters are used to wrap the injected file content, nor are there instructions telling the agent to treat the content as untrusted data.
  • Capability inventory: The skill is granted extensive capabilities, including full shell access (Bash), filesystem modification (Write, Edit), and network search/fetch tools.
  • Sanitization: The skill does not perform any validation, sanitization, or filtering of the file content before it is read into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — planning-with-files