skills/duc01226/easyplatform/plan-two/Gen Agent Trust Hub

plan-two

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided task descriptions through the $ARGUMENTS variable and reads codebase files via the scout agent. This creates a surface for indirect prompt injection where malicious instructions embedded in the task or codebase could attempt to influence the agent. However, the skill mitigates this through a mandatory planning-only constraint and explicit human-in-the-loop validation steps (/plan-review and /plan-validate).
  • [COMMAND_EXECUTION]: The skill instructs the agent to create directories and tasks using the TaskCreate tool. These are standard project management operations within the agent environment and do not involve the execution of arbitrary or elevated shell commands.
  • [SAFE]: The skill contains explicit prohibitions against implementing or executing code changes (DO NOT implement or execute any code changes), focusing entirely on the research and documentation phase of development.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 07:25 AM
Security Audit — agent-trust-hub — plan-two