write-plan
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from
.beagle/concepts/<slug>/spec.mdand other project files (likeAGENTS.mdandCLAUDE.md) to generate a structured implementation plan. If these files are compromised or contain malicious instructions, the agent might incorporate harmful shell commands or code snippets into the final plan. - Ingestion points:
.beagle/concepts/<slug>/spec.md,AGENTS.md,CLAUDE.md, and relevant source code. - Boundary markers: No explicit markers or "ignore embedded instructions" warnings are present during the ingestion of the specification file or project conventions.
- Capability inventory: The skill can read and write files and generate handoff prompts for downstream subagents.
- Sanitization: The workflow includes a manual user review gate before the plan is written to disk, which acts as a mitigation against automated injection.
- [COMMAND_EXECUTION]: The agent is instructed to generate exact, copy-pasteable shell commands (e.g.,
git add,git commit, and project-specific test runner commands) within the implementation plan. While the agent does not execute these commands itself, they are presented as authoritative instructions for the user or a downstream executor agent.
Audit Metadata