planning

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions in references/codebase-understanding.md direct the agent to "Analyze dotenv files and configuration." Reading .env files is a high-risk activity as they often contain sensitive secrets, API keys, and credentials.
  • [EXTERNAL_DOWNLOADS]: The references/research-phase.md file instructs the agent to use the repomix --remote command to fetch and summarize content from external GitHub repositories, which involves downloading data from untrusted sources into the agent's context.
  • [COMMAND_EXECUTION]: The skill requires the use of shell-based tools, including gh for GitHub metadata analysis and repomix for repository summarization, as specified in references/research-phase.md.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it is designed to ingest and process data from external GitHub repositories and local codebase files without implementing security boundaries or sanitization.
  • Ingestion points: Environment configuration files (.env), local codebase files, and remote GitHub repositories fetched via repomix (identified in references/codebase-understanding.md and references/research-phase.md).
  • Boundary markers: Absent. The instructions do not define delimiters or provide guidance to ignore embedded instructions within the processed data.
  • Capability inventory: The agent can execute shell commands (gh, repomix), write multiple plan and report files to the filesystem, and spawn specialized sub-agents (scout, researcher, debugger).
  • Sanitization: Absent. There are no instructions for the agent to sanitize or escape content from external files or repositories before interpretation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — planning