write-plan
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscated content, or unauthorized network operations were identified in the skill's instructions or metadata.
- [PROMPT_INJECTION]: The skill processes user-controlled data, identifying an indirect prompt injection surface.
- Ingestion points: The skill reads implementation details from requirements.md, design.md, docs/agents/project.md, docs/product/guidelines.md, and docs/architecture/.
- Boundary markers: The skill lacks explicit boundary markers for ingested content and is instructed to copy sections verbatim into the tasks.md file.
- Capability inventory: The skill is capable of repository file writes (creating docs/specs/.../tasks.md), dispatching subagents for code review, and publishing to issue trackers.
- Sanitization: No explicit sanitization or filtering is applied to the requirement text before it is incorporated into the implementation plan.
Audit Metadata