plan-review-experience
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a set of text-based instructions for a plan review process and does not contain any executable code, shell commands, or network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze project plans and specifications provided as external data.
- Ingestion points: Step 1 identifies the plan file, spec, mockups, and API specs as inputs.
- Boundary markers: No explicit delimiters or boundary markers for untrusted input are defined.
- Capability inventory: No file system writes, network requests, or subprocess executions were found in the skill definition.
- Sanitization: No sanitization or filtering logic is present.
- Analysis: Although the skill processes untrusted input, the total lack of exploitable capabilities (network, file-write, command execution) ensures that the risk is negligible.
Audit Metadata