ce-plan

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the gh and linear command-line interfaces to export generated plan files into tracked issues. It also employs shell utilities such as mktemp and cat to manage temporary data during the deepening and synthesis phases.
  • [DATA_EXFILTRATION]: Functionally sends the contents of the generated implementation plans to external services (GitHub or Linear) when the user elects to create an issue. This transmission is a documented feature and utilizes well-known technology service providers.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is instructed to treat external requirements documents (docs/brainstorms/) and user-provided feature descriptions as authoritative inputs. To mitigate this risk, the workflow implements a mandatory evidence chain: it ingests data via structured XML-like delimiters, possesses a defined inventory of capabilities (shell execution and sub-agent dispatch), and requires a multi-persona sanitization process (Phase 5.3) to review the final plan before any external or implementation actions are taken.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:03 AM
Security Audit — agent-trust-hub — ce-plan