skills/h00mankind/workflow/plan/Gen Agent Trust Hub

plan

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the GitHub CLI via gh issue create to publish generated task slices as issues. This behavior is documented and aligns with the skill's stated purpose of automating the transition from planning to execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests and processes untrusted data from the local codebase and documentation folder to inform its planning logic.
  • Ingestion points: Reads content from docs/CONTEXT.md, docs/adr/, and the general codebase.
  • Boundary markers: The instructions do not provide explicit delimiters or instructions to the agent to ignore potentially malicious embedded commands within the files it analyzes.
  • Capability inventory: The skill possesses file-writing capabilities (creating and updating .md files in the docs/ directory) and shell command execution (gh issue create).
  • Sanitization: There are no mentioned filters or sanitization steps to validate content extracted from the codebase before it is interpolated into the agent's planning context or published as issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 02:53 AM
Security Audit — agent-trust-hub — plan