plan-orchestrate
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from a plan document and interpolates it into generated orchestration commands.
- Ingestion points: The
<plan-doc-path>parameter (SKILL.md, Phase 0) allows the skill to read arbitrary files. - Boundary markers: The skill does not implement robust boundary markers or safety instructions in the emitted task descriptions to prevent the downstream agents from following instructions embedded within the plan text.
- Capability inventory: The skill generates commands for the
/orchestratetool, which can execute file writes, network operations, and other tool-assisted tasks via its constituent agents. - Sanitization: While the skill escapes double quotes (
\"), it lacks semantic sanitization to filter out malicious instructions (e.g., 'ignore previous instructions') embedded in the input plan.
Audit Metadata