executing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary process involves reading an external plan file and executing the steps exactly as written. This creates an attack surface (Category 8c) where malicious instructions embedded in a plan file could influence agent behavior. Although the skill mandates a critical review by the agent before starting, this does not fully eliminate the risk of the agent following sophisticated or obfuscated malicious instructions in the plan.
Audit Metadata