plan-tasks
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from design documents in the
Docs/designs/folder, which creates a surface for indirect prompt injection. A malicious design document could contain hidden instructions designed to influence the agent's task-generation logic. - [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis:
- Ingestion points: Markdown files located in the
Docs/designs/directory (referenced in SKILL.md). - Boundary markers: No delimiters or 'ignore-embedded-instructions' warnings are defined for the source documents.
- Capability inventory: The skill involves reading existing design documentation and writing implementation plans to the
Docs/In-Progress/folder. - Sanitization: No sanitization or input validation is applied to the content of the design documents before they are processed by the agent.
Audit Metadata