interview-and-create-plan

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the opencode-ralph-rlm plan-path shell command to identify the correct file path for writing the plan. This command is part of the integrated toolset for the Ralph RLM environment.\n- [PROMPT_INJECTION]: The skill defines a process where untrusted data from repository exploration and user interviews is used to generate a PLAN.md file, which then serves as the high-level instruction set for future autonomous worker agents. This configuration presents an indirect prompt injection surface.\n
  • Ingestion points: Repository source code and user-provided interview responses (SKILL.md).\n
  • Boundary markers: No specific delimiters or instruction-ignore warnings are implemented in the generated output.\n
  • Capability inventory: The skill possesses file writing capabilities (PLAN.md, ralph.json) and command execution via the opencode-ralph-rlm CLI tool.\n
  • Sanitization: There are no explicit filtering or sanitization steps mentioned for the data ingested during the interview phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 04:43 PM
Security Audit — agent-trust-hub — interview-and-create-plan