qstack-plan-to-html
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process Markdown drafts and HTML plans to resolve open questions and generate execution board cards. This creates an attack surface where malicious instructions embedded in a plan could be interpreted as valid requirements or decisions.
- Ingestion points: Reads Markdown files and existing plan.html documents from the repository.
- Boundary markers: None identified in the skill instructions or templates to distinguish plan content from agent instructions.
- Capability inventory: Performs file writes via printf, modifies file permissions, and invokes platform-integrated sibling skills for auditing and prototyping.
- Sanitization: The skill does not implement specific filtering or sanitization to prevent the AI from obeying instructions found within the plan data.
- [DYNAMIC_EXECUTION]: The skill uses printf to generate and append JavaScript event data to board-events.js. This file is then executed by the browser via a script tag in the generated HTML plan to populate the execution board UI. The agent also uses node --check to validate the syntax of these generated files.
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to fetch font assets from fonts.googleapis.com. This involves communication with a well-known and trusted service for standard asset management.
- [COMMAND_EXECUTION]: The skill marks its own distributed scripts as executable using chmod +x and provides a script to serve plan files using a local Python HTTP server for previewing purposes.
Audit Metadata