planning-with-files
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines several automation hooks in the YAML frontmatter that trigger shell commands during the agent session. These include using
catto display file contents in thePreToolUsehook and executing a local validation scriptcheck-complete.shin theStophook. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by automatically ingesting the content of filesystem files into the active agent context.
- Ingestion points: The
PreToolUsehook inSKILL.mdautomatically reads and displays the beginning of thetask_plan.mdfile from the working directory before everyWrite,Edit, orBashcommand. - Boundary markers: No boundary markers or delimiters are used to wrap the injected file content, nor are there instructions telling the agent to treat the content as untrusted data.
- Capability inventory: The skill is granted extensive capabilities, including full shell access (
Bash), filesystem modification (Write,Edit), and network search/fetch tools. - Sanitization: The skill does not perform any validation, sanitization, or filtering of the file content before it is read into the agent's context.
Audit Metadata