consult-project-plan
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate project management tasks by reading local configuration files and generating a markdown report. It uses vendor-provided scripts located within the plugin root for data discovery and graph processing.
- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection (Category 8) by interpolating untrusted field data into the generated report.
- Ingestion points: deliverable metadata from field.json files.
- Boundary markers: None identified.
- Capability inventory: Subprocess calls via Bash/Python and file system writes.
- Sanitization: Not explicitly performed on interpolated strings. This is considered low risk given the internal nature of the tool.
Audit Metadata