write-plan

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from .beagle/concepts/<slug>/spec.md and other project files (like AGENTS.md and CLAUDE.md) to generate a structured implementation plan. If these files are compromised or contain malicious instructions, the agent might incorporate harmful shell commands or code snippets into the final plan.
  • Ingestion points: .beagle/concepts/<slug>/spec.md, AGENTS.md, CLAUDE.md, and relevant source code.
  • Boundary markers: No explicit markers or "ignore embedded instructions" warnings are present during the ingestion of the specification file or project conventions.
  • Capability inventory: The skill can read and write files and generate handoff prompts for downstream subagents.
  • Sanitization: The workflow includes a manual user review gate before the plan is written to disk, which acts as a mitigation against automated injection.
  • [COMMAND_EXECUTION]: The agent is instructed to generate exact, copy-pasteable shell commands (e.g., git add, git commit, and project-specific test runner commands) within the implementation plan. While the agent does not execute these commands itself, they are presented as authoritative instructions for the user or a downstream executor agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — write-plan