executing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes implementation plans that may contain instructions from untrusted sources, creating a surface for indirect prompt injection.
  • Ingestion points: The process begins by reading a plan file in Step 1.
  • Boundary markers: The skill does not define specific delimiters or 'ignore instructions' warnings for the content read from the plan files.
  • Capability inventory: The skill is intended to 'execute all tasks' within the plan, which includes using tools like TodoWrite and calling other sub-skills like finishing-a-development-branch.
  • Sanitization: There is no mention of sanitization, escaping, or validation of the content provided in the plan files before the agent executes the steps exactly as written.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — executing-plans