better-planning-design
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes external project documents (PRDs and Briefs) to generate architecture designs and implementation plans. Malicious content within these source documents could potentially influence the agent's decisions. The skill lacks explicit instructions for the agent to use boundary markers or to sanitize content ingested from these files.
- [COMMAND_EXECUTION]: The skill uses shell commands for file system operations, version control (git commit), and suggests user-initiated commands such as
openorxdg-opento view generated visual artifacts. These are standard functional requirements for a documentation and planning tool.
Audit Metadata