skills/grahama1970/agent-skills/plan/Gen Agent Trust Hub

plan

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted user input (goals and task files) that could contain malicious instructions designed to influence the agent's behavior during the planning phase.
  • Ingestion points: The goal argument and the contents of requirements files processed by plan.py via the --validate or --analyze-deps flags.
  • Boundary markers: The skill does not implement specific delimiters or safety instructions (e.g., "ignore embedded instructions") when interpolating user data into the planning context.
  • Capability inventory: The skill allows the use of powerful tools including Bash, Write, and Edit, and explicitly instructs the agent to execute shell commands for capability checks and task monitoring.
  • Sanitization: No sanitization or escaping is performed on the user-provided goal or file content beyond basic regex-based extraction for dependency analysis.
  • [COMMAND_EXECUTION]: The skill documentation instructs the agent to perform local filesystem operations and execute CLI tools to verify project state and monitor task execution.
  • Evidence: SKILL.md contains instructions for the agent to run ls ~/.pi/skills/*/SKILL.md | xargs grep -l to check for capability overlaps and memory-agent recall to search for existing solutions.
  • Context: These operations are used for the legitimate purpose of preventing architectural redundancy and ensuring project consistency, which is the primary goal of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — plan