planning-with-files

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell hooks to automate context management. Specifically, the PreToolUse hook executes cat task_plan.md to refresh the agent's memory, and the Stop hook runs a local script scripts/check-complete.sh to verify task completion. These commands are localized to the project environment and perform benign operations.
  • [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by design. It encourages the agent to ingest untrusted data from the web (via WebSearch and WebFetch) and record findings in local markdown files. These files are subsequently read back into the agent's primary context during tool use. 1. Ingestion points: task_plan.md and findings.md serve as storage for data retrieved from external sources (SKILL.md). 2. Boundary markers: No explicit delimiters or instructions are used within the files to isolate untrusted content from the agent's core instructions. 3. Capability inventory: The skill allows Bash, Write, Edit, and Read operations, which can be influenced by the content of the planning files. 4. Sanitization: The skill does not implement automated sanitization of external content before it is stored or re-injected into the context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — planning-with-files