phase-plan
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external project files like plan.toml and design.md to generate concrete task breakdowns, which creates an indirect prompt injection surface. Ingestion points: plan.toml, design.md, and slice-nnn.md. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the ingested content. Capability inventory: Uses the doctrine CLI tool and the /execute command. Sanitization: No content filtering or validation is described for the input files.
- [COMMAND_EXECUTION]: The skill instructs the agent to run specific commands using the doctrine CLI (doctrine slice research, doctrine slice phase). These commands are part of the intended project workflow and do not involve arbitrary or unsafe shell execution patterns.
Audit Metadata