nerd-plan
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest repository evidence, design choices, and diagnostic data to generate implementation plans. This process is susceptible to indirect prompt injection if the source data (such as code comments or documentation in the repository) contains malicious instructions designed to alter the generated tasks or commands. \n
- Ingestion points: Repository evidence from
nerd-explore, design directions fromnerd-brainstorm, and root-cause evidence fromnerd-diagnose. \n - Boundary markers: The skill uses a structured 'Plan Format' and 'Focus Record' template to delineate different types of information and isolate sub-agent instructions. \n
- Capability inventory: The skill has the capability to write Markdown files to the
docs/plans/directory and generates shell commands intended for later execution by the user or another agent. \n - Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content ingested from external repository sources.
Audit Metadata