generate-project-plan

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from PRD documents and codebase files, creating a surface for indirect prompt injection.\n- Ingestion points: PRD content and codebase grounding (Step 1).\n- Boundary markers: No explicit delimiters used to isolate external text.\n- Capability inventory: Board creation via use_figma, file creation, and diagram generation.\n- Sanitization: Risks are strongly mitigated by mandatory human-in-the-loop checkpoints and visual verification before and after all write operations.\n- [COMMAND_EXECUTION]: The skill generates and executes Javascript code within the Figma environment using the use_figma tool.\n- Evidence: Multiple steps utilize use_figma to run agent-generated scripts based on provided templates.\n- Mitigation: The skill employs structured templates and operational rules to ensure scripts remain within the intended scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:29 PM
Security Audit — agent-trust-hub — generate-project-plan