executing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and execute steps from an external 'plan file', which constitutes an attack surface for instructions embedded in data. This is an inherent part of the skill's purpose to follow user-provided plans.
  • Ingestion points: Step 1.1 explicitly instructs the agent to 'Read plan file'.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the plan content.
  • Capability inventory: The skill facilitates task execution which, depending on the plan content, could involve file modifications or command execution.
  • Sanitization: No automated sanitization is described, although the process requires a manual 'critical review' by the agent and reporting to a human partner for feedback between batches.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — executing-plans