planning-with-files

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill automatically displays the content of task_plan.md to the agent before certain tool operations using a PreToolUse hook. Because the skill's instructions encourage logging research findings and browser data into these files, an attacker could potentially inject instructions via external content that the agent then reads back into its high-attention context window.
  • Ingestion points: The PreToolUse hook in SKILL.md executes cat task_plan.md to refresh the agent's attention window.
  • Boundary markers: The displayed content lacks explicit delimiters or instructions to the agent to treat the file content as data rather than instructions.
  • Capability inventory: The skill possesses high-privilege capabilities including Bash, Write, Edit, WebFetch, and WebSearch.
  • Sanitization: There is no process for sanitizing or escaping content before it is written to or read from the planning files.
  • [COMMAND_EXECUTION]: The skill executes local shell scripts for initialization (scripts/init-session.sh) and completion verification (scripts/check-complete.sh). These scripts perform standard filesystem operations such as template-based file creation and string matching with grep, and they do not process unvalidated remote input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — planning-with-files