skills/iuliandita/skills/plan-review/Gen Agent Trust Hub

plan-review

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses structured lenses (Jekyll and Hyde) for critiquing plans. While Hyde is described as a 'ruthless shadow-advisor,' this is a role-play framework for analytical critique of user-provided content and does not attempt to bypass agent safety filters or instructions.
  • [DATA_EXFILTRATION]: There are no network operations or external data transfer mechanisms. The skill instructs the agent to read local plans and write decision records to specific local documentation paths.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote script fetching, package installation, or shell command execution. It operates entirely on text-based analysis and template generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided plans as input for analysis. While this represents a data ingestion surface, the skill lacks high-privilege capabilities such as shell execution or network requests, effectively mitigating the risk of indirect prompt injection attacks.
  • [OBFUSCATION]: All files were inspected for hidden text, zero-width characters, and encoded sequences. No obfuscation techniques were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:56 AM
Security Audit — agent-trust-hub — plan-review