ce-plan

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructional markers such as "IMPORTANT" and "CRITICAL" to enforce strict formatting rules, such as the requirement for repo-relative file paths. These directives are intended to maintain the portability and quality of the generated plans and do not constitute an attempt to bypass agent safety or personality filters.
  • [EXTERNAL_DOWNLOADS]: The workflow incorporates research phases where the agent dispatches specialized sub-agents to fetch external documentation and industry best practices. This behavior is triggered by task complexity and is used to ground planning decisions in current technical knowledge.
  • [COMMAND_EXECUTION]: The skill uses local shell commands for legitimate project management tasks, specifically gh issue create and linear issue create for issue tracking, and mktemp for creating temporary research artifacts. These commands are standard for the tool's intended use case.
  • [DATA_EXFILTRATION]: The plan generation process includes a feature to upload documents to a vendor-managed web application ("Every's Proof") for collaborative review. This is an explicit, user-triggered feature that utilizes the author's own ecosystem and infrastructure for document sharing and iteration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:48 PM