weekly-plan
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external files and tool outputs without explicit boundary markers or sanitization. \n- Ingestion points: The skill reads OKRs, PRDs, and launch plans from
thoughts/shared/pm/directories, and queries Calendar, Linear, and Analytics MCPs. \n- Boundary markers: There are no instructions to use delimiters or ignore potentially malicious commands embedded within the processed strategic documents or task descriptions. \n- Capability inventory: The agent has the ability to write files to the local system and interact with external APIs via MCPs. \n- Sanitization: The instructions do not specify any validation or filtering of the content extracted from the files is performed before it is used to influence the agent's behavior.
Audit Metadata