skills/jei-skappa/skills/plan-strict/Gen Agent Trust Hub

plan-strict

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface because it processes untrusted content from external sources to define plan tasks.
  • Ingestion points: The agent reads local project documents (specs, proposals, decision logs) and fetches remote content from GitHub issue URLs to use as upstream input.
  • Boundary markers: The instructions do not mandate the use of delimiters, such as XML tags or unique markers, nor do they instruct the agent to ignore or isolate potentially malicious instructions embedded within the ingested data.
  • Capability inventory: The agent has permissions to create directory structures and write multiple files to the local filesystem (index and task files) and can perform network operations to retrieve issue data.
  • Sanitization: There are no specified procedures for validating, escaping, or sanitizing the content of the external artifacts before they are interpolated into the planning workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:33 PM
Security Audit — agent-trust-hub — plan-strict