writing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external specifications to generate code and commands for implementation plans. This provides a surface for indirect prompt injection where a malicious requirement could influence the generated output.
  • Ingestion points: The skill processes a 'spec' or 'requirements' document provided as input to the writing task.
  • Boundary markers: The instructions do not define explicit boundary markers or 'ignore' instructions to isolate the input spec from the skill's operational logic.
  • Capability inventory: The skill generates plans containing functional Python code and shell commands (git, pytest) that are intended for immediate execution by subagents or via the executing-plans sub-skill.
  • Sanitization: There is no evidence of input validation, escaping, or sanitization for the content of the provided specifications.
  • [DYNAMIC_EXECUTION]: The skill generates implementation plans that include Python code snippets and shell scripts. These artifacts are explicitly designed to be executed via subagents or the executing-plans skill, representing a script generation and execution workflow.
  • [COMMAND_EXECUTION]: The task templates include direct shell command execution instructions, specifically using git for version control management and pytest for test execution within the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — writing-plans