executing-plans
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to load and execute tasks from external plan files, which constitutes a surface for indirect prompt injection attack vectors.
- Ingestion points: Step 1 involves reading an external implementation plan file.
- Boundary markers: The instructions do not specify the use of delimiters or escaping mechanisms to isolate the ingested plan content.
- Capability inventory: The skill facilitates the batch execution of tasks which may include environment modifications or tool calls based on the plan's instructions.
- Sanitization: The skill mitigates risks by requiring a 'critical review' of the plan before execution and providing explicit 'STOP' conditions for ambiguous or failing tasks.
- [NO_CODE]: The skill consists entirely of markdown instructions and metadata; no scripts, binaries, or accompanying source code files are included.
Audit Metadata