skills/ingpoc/skills/execplan/Gen Agent Trust Hub

execplan

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill contains hardcoded absolute file paths in the Constants section (e.g., C:/Users/gurusharan.gupta/Agents/...) which exposes the host's directory structure and local username.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface in Step 1: Determine Project Context. It reads untrusted files from the current directory (such as CLAUDE.md, package.json, and requirements.txt) without boundary markers or sanitization, potentially allowing an attacker to influence the generated ExecPlan or subsequent command execution.
  • [COMMAND_EXECUTION]: The instructions encourage high agent autonomy by directing the agent to "not prompt for next steps" and "resolve ambiguities autonomously" when following a plan. This increases the risk that malicious instructions injected into a plan will be executed without user oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 09:45 AM
Security Audit — agent-trust-hub — execplan