weekly-plan

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external files and tool outputs without explicit boundary markers or sanitization. \n- Ingestion points: The skill reads OKRs, PRDs, and launch plans from thoughts/shared/pm/ directories, and queries Calendar, Linear, and Analytics MCPs. \n- Boundary markers: There are no instructions to use delimiters or ignore potentially malicious commands embedded within the processed strategic documents or task descriptions. \n- Capability inventory: The agent has the ability to write files to the local system and interact with external APIs via MCPs. \n- Sanitization: The instructions do not specify any validation or filtering of the content extracted from the files is performed before it is used to influence the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:28 PM
Security Audit — agent-trust-hub — weekly-plan