plan-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads plan files from the file system and provides their content to sub-agents, which can be influenced by malicious instructions embedded in the plans. Ingestion points: Step 1 involves reading plan files from docs/claudekit/plans/. Boundary markers: No explicit delimiters are used to wrap the untrusted plan content when passed to the architecture and experience reviewers. Capability inventory: The skill possesses the ability to invoke other agents and perform file modifications via the Edit tool. Sanitization: There is no evidence of content filtering or sanitization being applied to the ingested plan files.
Audit Metadata