planning-with-files
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill automatically displays the content of
task_plan.mdto the agent before certain tool operations using aPreToolUsehook. Because the skill's instructions encourage logging research findings and browser data into these files, an attacker could potentially inject instructions via external content that the agent then reads back into its high-attention context window. - Ingestion points: The
PreToolUsehook inSKILL.mdexecutescat task_plan.mdto refresh the agent's attention window. - Boundary markers: The displayed content lacks explicit delimiters or instructions to the agent to treat the file content as data rather than instructions.
- Capability inventory: The skill possesses high-privilege capabilities including
Bash,Write,Edit,WebFetch, andWebSearch. - Sanitization: There is no process for sanitizing or escaping content before it is written to or read from the planning files.
- [COMMAND_EXECUTION]: The skill executes local shell scripts for initialization (
scripts/init-session.sh) and completion verification (scripts/check-complete.sh). These scripts perform standard filesystem operations such as template-based file creation and string matching withgrep, and they do not process unvalidated remote input.
Audit Metadata