executing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes implementation plans that may contain instructions from untrusted sources, creating a surface for indirect prompt injection.
- Ingestion points: The process begins by reading a plan file in Step 1.
- Boundary markers: The skill does not define specific delimiters or 'ignore instructions' warnings for the content read from the plan files.
- Capability inventory: The skill is intended to 'execute all tasks' within the plan, which includes using tools like
TodoWriteand calling other sub-skills likefinishing-a-development-branch. - Sanitization: There is no mention of sanitization, escaping, or validation of the content provided in the plan files before the agent executes the steps exactly as written.
Audit Metadata