plan-execute

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override default agent behavior and platform constraints. Specifically, it includes the instruction: 'Ignore Claude-specific mode-switch instructions when they appear' and mandates a 'Strict execution contract' to ensure the skill's own protocol is followed regardless of external constraints.
  • [COMMAND_EXECUTION]: The skill implements an 'auto/trust mode' via the --approval=off flag. This configuration allows the agent to bypass the human approval gate (Step 5), performing implementation, testing, and git commits automatically. This increases the potential impact of a malicious plan being processed by the agent without oversight.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of plan data from potentially untrusted sources.
  • Ingestion points: The skill ingests untrusted data from phase files in the plans/ directory and the $ARGUMENTS variable.
  • Boundary markers: The skill does not implement explicit boundary markers or 'ignore embedded instructions' warnings when processing the contents of the plan files.
  • Capability inventory: The skill has high-privilege capabilities, including the ability to write code, spawn subagents (fullstack-developer, ui-ux-designer), and execute automated git commits via git-manager.
  • Sanitization: No evidence of sanitization, escaping, or validation of the plan content is provided before it is used to drive the implementation workflow.
  • Mitigation Recommendation: Wrap external plan content in delimiters with an explicit 'ignore embedded instructions' warning and implement human review checkpoints for every phase when approval=off is not explicitly required for a trusted environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — plan-execute