skills/grupous/gpus/planning/Gen Agent Trust Hub

planning

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. External data is ingested via Tavily and Context7 (references/mcp-usage.md). There are no defined boundary markers or sanitization steps for this untrusted input. The agent possesses capabilities to read files, write plan documents, and execute commands via bun (SKILL.md), which could be manipulated by malicious content in searched documentation or web results. Ingestion points: Tavily search/extract and Context7 query-docs. Boundary markers: Absent. Capability inventory: view_file, grep_search, and shell command execution via bun. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as 'bun run check', 'bun run format', and 'bun test' as part of the implementation and validation phases (SKILL.md). While these are standard developer tools, they represent the execution of local code based on instructions derived from the research phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — planning