consult-project-plan

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate project management tasks by reading local configuration files and generating a markdown report. It uses vendor-provided scripts located within the plugin root for data discovery and graph processing.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection (Category 8) by interpolating untrusted field data into the generated report.
  • Ingestion points: deliverable metadata from field.json files.
  • Boundary markers: None identified.
  • Capability inventory: Subprocess calls via Bash/Python and file system writes.
  • Sanitization: Not explicitly performed on interpolated strings. This is considered low risk given the internal nature of the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — consult-project-plan