review-plan
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted implementation plans provided via the 'Path' argument. If these files contain malicious instructions disguised as technical plans, they could potentially influence the agent's behavior during the review phase.
- Ingestion points: The skill reads the content of a user-specified plan file in 'Step 1' and 'Step 3'.
- Boundary markers: The skill employs an 'Anti-confabulation' gate that requires the agent to echo the exact artifact text being judged using blockquotes, which helps maintain context and reduce the success of embedded instructions.
- Capability inventory: The skill is capable of reading local files, searching the codebase for types and APIs, and writing a review report to the filesystem.
- Sanitization: The skill mandates a specific review structure and multi-lens approach, but it does not explicitly sanitize the plan content before processing; however, it includes an explicit rule to 'Never auto-execute plan', requiring user choice before any implementation occurs.
Audit Metadata