writing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided specifications and requirements to generate implementation plans. These plans contain shell commands and Python code intended to be executed by the agent or subsequent sub-skills (e.g.,
ltk:executing-plans). The lack of explicit boundary markers or input sanitization allows for a potential attack surface where malicious input could influence the generated commands or code. - Ingestion points: User-supplied task specifications and requirements provided during the planning phase (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the input data are defined.
- Capability inventory: The skill instructions generate implementation plans involving file creation/modification,
gitcommands, andpytestexecution (SKILL.md). - Sanitization: No sanitization, validation, or escaping of the user-provided requirements is performed before interpolation into the plan template.
- [COMMAND_EXECUTION]: The skill provides templates that generate shell commands for version control (
git add,git commit) and for running tests (pytest). These are standard development operations and are explicitly documented for use within implementation plans.
Audit Metadata