dev-planning

Fail

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run npx ai-devkit@latest multiple times (SKILL.md). This command fetches and executes the latest version of the ai-devkit package from the public npm registry at runtime. Because the version is not pinned (using @latest), the skill is susceptible to supply chain attacks where a malicious update to the package could lead to arbitrary code execution on the user's system.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution via the npx utility for linting, feature path resolution, and project initialization throughout the planning lifecycle.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from external sources. 1. Ingestion points: The skill reads requirements, design, and testing documents from the file system (SKILL.md, lines 19, 36). 2. Boundary markers: There are no explicit delimiters or instructions to ignore embedded malicious prompts within the processed documentation. 3. Capability inventory: The skill can execute shell commands via npx and write to the file system to update planning documents. 4. Sanitization: No sanitization, validation, or filtering of the content from the external documents is performed before it is used to generate implementation tasks.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 14, 2026, 12:16 PM
Security Audit — agent-trust-hub — dev-planning