executing-plans
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a robust workflow for task execution that emphasizes isolation through git worktrees and includes explicit protocols for human intervention when blockers are encountered.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and execute externally defined implementation plans, which creates an inherent surface for indirect instructions.
- Ingestion points: Processes implementation plan files as described in Step 1 of SKILL.md.
- Boundary markers: Employs a mandatory critical review step and "Stop and Ask" instructions to mitigate the risk of following unsafe or unclear instructions.
- Capability inventory: Manages task states and utilizes sub-skills for workspace isolation and branch finalization.
- Sanitization: No programmatic sanitization is defined; the skill relies on the agent's critical analysis and verification steps.
Audit Metadata