executing-plans

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to load and execute tasks from external plan files, which constitutes a surface for indirect prompt injection attack vectors.
  • Ingestion points: Step 1 involves reading an external implementation plan file.
  • Boundary markers: The instructions do not specify the use of delimiters or escaping mechanisms to isolate the ingested plan content.
  • Capability inventory: The skill facilitates the batch execution of tasks which may include environment modifications or tool calls based on the plan's instructions.
  • Sanitization: The skill mitigates risks by requiring a 'critical review' of the plan before execution and providing explicit 'STOP' conditions for ambiguous or failing tasks.
  • [NO_CODE]: The skill consists entirely of markdown instructions and metadata; no scripts, binaries, or accompanying source code files are included.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — executing-plans