generate-project-plan
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from PRD documents and codebase files, creating a surface for indirect prompt injection.\n- Ingestion points: PRD content and codebase grounding (Step 1).\n- Boundary markers: No explicit delimiters used to isolate external text.\n- Capability inventory: Board creation via
use_figma, file creation, and diagram generation.\n- Sanitization: Risks are strongly mitigated by mandatory human-in-the-loop checkpoints and visual verification before and after all write operations.\n- [COMMAND_EXECUTION]: The skill generates and executes Javascript code within the Figma environment using theuse_figmatool.\n- Evidence: Multiple steps utilizeuse_figmato run agent-generated scripts based on provided templates.\n- Mitigation: The skill employs structured templates and operational rules to ensure scripts remain within the intended scope.
Audit Metadata