plan
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted user input (goals and task files) that could contain malicious instructions designed to influence the agent's behavior during the planning phase.
- Ingestion points: The
goalargument and the contents of requirements files processed byplan.pyvia the--validateor--analyze-depsflags. - Boundary markers: The skill does not implement specific delimiters or safety instructions (e.g., "ignore embedded instructions") when interpolating user data into the planning context.
- Capability inventory: The skill allows the use of powerful tools including
Bash,Write, andEdit, and explicitly instructs the agent to execute shell commands for capability checks and task monitoring. - Sanitization: No sanitization or escaping is performed on the user-provided goal or file content beyond basic regex-based extraction for dependency analysis.
- [COMMAND_EXECUTION]: The skill documentation instructs the agent to perform local filesystem operations and execute CLI tools to verify project state and monitor task execution.
- Evidence:
SKILL.mdcontains instructions for the agent to runls ~/.pi/skills/*/SKILL.md | xargs grep -lto check for capability overlaps andmemory-agent recallto search for existing solutions. - Context: These operations are used for the legitimate purpose of preventing architectural redundancy and ensuring project consistency, which is the primary goal of the skill.
Audit Metadata