writing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional content and templates for plan documentation. It does not perform any file system operations (other than defining target paths for documentation), network requests, or command execution.
  • [NO_CODE]: No scripts or binary executables are included in this skill; it is purely composed of markdown instructions and YAML configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external specifications to generate plans, which presents a surface for indirect prompt injection. However, given its intended use as a documentation tool and the absence of direct execution capabilities, the risk is minimal.
  • Ingestion points: External project specifications or requirements referenced in the SKILL.md body.
  • Boundary markers: None explicitly provided in the templates to separate spec instructions from planning logic.
  • Capability inventory: Writing implementation plan files to the docs/ directory.
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:02 AM
Security Audit — agent-trust-hub — writing-plans