executing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to read external plan files and follow their instructions exactly, which creates an attack surface for indirect prompt injection where malicious instructions could be embedded in the plan data.
- Ingestion points: Step 1 in
SKILL.mdinstructs the agent to "Read plan file". - Boundary markers: Absent. There are no instructions or delimiters provided to separate the plan content from the agent's core instructions or to ignore embedded commands.
- Capability inventory: The skill gives the agent authority to "Follow each step exactly" and "Run verifications" as defined by the plan, which generally involves file modification and command execution tools provided by the platform.
- Sanitization: Absent. There is no step to validate, filter, or escape content from the implementation plan before execution.
Audit Metadata