better-planning-brainstorm

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project data including code, documentation, and git history to generate digests and brainstorming records. This ingestion creates a risk surface for indirect prompt injection, where malicious instructions hidden in the codebase could influence the agent's behavior. The ingestion points include the docs/better-planning/ directory and project source files. While the skill uses structured markdown headers, it does not explicitly instruct the agent to sanitize or ignore instructions within these ingested files. The skill has capabilities for file system operations and git interactions.
  • [DYNAMIC_EXECUTION]: The skill generates interactive HTML artifacts with embedded vanilla JavaScript for local feedback capture. The template assets/overview-template.html contains script logic for localStorage and JSON export. While the generated code is limited to user-controlled review surfaces, runtime generation of executable script content represents a dynamic execution pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:29 PM
Security Audit — agent-trust-hub — better-planning-brainstorm