plan-orchestrate

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from a plan document and interpolates it into generated orchestration commands.
  • Ingestion points: The <plan-doc-path> parameter (SKILL.md, Phase 0) allows the skill to read arbitrary files.
  • Boundary markers: The skill does not implement robust boundary markers or safety instructions in the emitted task descriptions to prevent the downstream agents from following instructions embedded within the plan text.
  • Capability inventory: The skill generates commands for the /orchestrate tool, which can execute file writes, network operations, and other tool-assisted tasks via its constituent agents.
  • Sanitization: While the skill escapes double quotes (\"), it lacks semantic sanitization to filter out malicious instructions (e.g., 'ignore previous instructions') embedded in the input plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:56 PM
Security Audit — agent-trust-hub — plan-orchestrate