writing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external specifications to generate code and commands for implementation plans. This provides a surface for indirect prompt injection where a malicious requirement could influence the generated output.
- Ingestion points: The skill processes a 'spec' or 'requirements' document provided as input to the writing task.
- Boundary markers: The instructions do not define explicit boundary markers or 'ignore' instructions to isolate the input spec from the skill's operational logic.
- Capability inventory: The skill generates plans containing functional Python code and shell commands (git, pytest) that are intended for immediate execution by subagents or via the executing-plans sub-skill.
- Sanitization: There is no evidence of input validation, escaping, or sanitization for the content of the provided specifications.
- [DYNAMIC_EXECUTION]: The skill generates implementation plans that include Python code snippets and shell scripts. These artifacts are explicitly designed to be executed via subagents or the
executing-plansskill, representing a script generation and execution workflow. - [COMMAND_EXECUTION]: The task templates include direct shell command execution instructions, specifically using
gitfor version control management andpytestfor test execution within the local environment.
Audit Metadata