writing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to include specific directives in its output documents (implementation plans) to trigger subsequent agent actions, such as 'REQUIRED SUB-SKILL: Use superpowers:executing-plans'. This facilitates a multi-step task chain where output from one session influences the instructions of the next.
  • Ingestion points: The skill processes user specifications to generate Implementation Plans in the docs/plans/ directory.
  • Boundary markers: No specific delimiters are enforced in the output templates to distinguish between data and instructions for downstream agents.
  • Capability inventory: The generated plans include shell commands for testing (pytest) and version control (git), along with Python code blocks.
  • Sanitization: No explicit sanitization or escaping of the user-provided requirements is described before interpolation into the plan document.
  • [COMMAND_EXECUTION]: The skill provides templates for the agent to generate shell commands for routine development tasks, specifically pytest for running unit tests and git for committing code changes.
  • [DYNAMIC_EXECUTION]: The skill generates implementation plans containing Python code snippets and shell commands meant for later execution. These follow standard templates for Test-Driven Development (TDD) and do not incorporate untrusted external sources during the generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — writing-plans