dev-planning
Fail
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run
npx ai-devkit@latestmultiple times (SKILL.md). This command fetches and executes the latest version of theai-devkitpackage from the public npm registry at runtime. Because the version is not pinned (using@latest), the skill is susceptible to supply chain attacks where a malicious update to the package could lead to arbitrary code execution on the user's system. - [COMMAND_EXECUTION]: The skill relies on shell command execution via the
npxutility for linting, feature path resolution, and project initialization throughout the planning lifecycle. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from external sources. 1. Ingestion points: The skill reads requirements, design, and testing documents from the file system (SKILL.md, lines 19, 36). 2. Boundary markers: There are no explicit delimiters or instructions to ignore embedded malicious prompts within the processed documentation. 3. Capability inventory: The skill can execute shell commands via
npxand write to the file system to update planning documents. 4. Sanitization: No sanitization, validation, or filtering of the content from the external documents is performed before it is used to generate implementation tasks.
Recommendations
- AI detected serious security threats
Audit Metadata