plan
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data in the form of project specifications, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads external content from
02-DOCS/wiki/sdd/specs/<slug>.mdand02-DOCS/wiki/sdd/constitution.mdto inform the planning process. - Boundary markers: The instructions include a manual check for
[NEEDS CLARIFICATION]markers in the input spec as a prerequisite for planning, and the output is strictly constrained by the providedreferences/plan-template.mdskeleton. - Capability inventory: The skill performs file-write operations to the local documentation directory (
02-DOCS/wiki/sdd/plans/<slug>.md). It does not have network access or administrative shell capabilities. - Sanitization: There is no explicit sanitization or filtering of the input spec text before it is used to populate the plan artifact.
Audit Metadata