plan-writing
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze project files using
Read,Glob, andGrepto generate task plans. This creates a surface where the agent could potentially ingest instructions hidden within a project's source code or documentation. - Ingestion points: Project files accessed via
Read,Glob, andGreptools. - Boundary markers: None specified in the instructions.
- Capability inventory: Limited to file read and search operations; no code execution or network transmission capabilities are granted in the skill configuration.
- Sanitization: None specified for external content.
- [COMMAND_EXECUTION]: The skill references several Python scripts (e.g.,
ux_audit.py,security_scan.py) as examples of project-specific tooling. However, the skill does not provide these scripts, nor does it command their execution or download. These are used purely as illustrative examples for different project types.
Audit Metadata