solutionize

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language such as 'non-negotiable' and 'strictly prohibited' to enforce a state machine. These instructions are functional constraints designed to prevent the agent from performing implementation tasks prematurely and do not attempt to bypass safety filters or extract system prompts.
  • [DATA_EXPOSURE]: The skill utilizes a tool to write plan files to a specific directory (~/.cursor/plans/). This is a legitimate operational requirement for the skill's stated purpose of managing development plans and does not involve accessing sensitive user credentials or system configurations.
  • [DATA_EXFILTRATION]: No network operations or data transmission patterns were detected. The skill operates entirely within the local environment and specifically disables model-driven tool invocation via frontmatter configuration.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided 'issue descriptions' and interpolates them into generated files, the risk is negligible because the skill explicitly prohibits execution-related capabilities (implementation, commits, etc.) during this phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 09:33 PM
Security Audit — agent-trust-hub — solutionize