executing-plans
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to load and execute instructions from a plan file, which creates a potential vulnerability if that file is sourced from or influenced by an untrusted party.
- Ingestion points: The agent is directed to read a plan file in Step 1 (SKILL.md).
- Boundary markers: The instructions do not define delimiters or provide warnings to the agent to disregard control-oriented instructions or malicious prompts embedded within the plan file.
- Capability inventory: The agent is instructed to "execute all tasks" and "follow each step exactly," which grants broad permission to use its available tools (such as file writing and command execution) to carry out potentially untrusted instructions.
- Sanitization: There are no verification or filtering steps mentioned for the content of the plan file before execution.
Audit Metadata