evo-executing-plans
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions.
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts, executable files, or package dependencies.
- [PROMPT_INJECTION]: The skill facilitates the processing of an external 'plan file', which creates an ingestion point for potentially untrusted instructions (Indirect Prompt Injection). 1. Ingestion points: 'Read plan file' in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Instructions to 'Execute tasks' and 'Run verifications'. 4. Sanitization: The risk is mitigated by explicit instructions for the agent to critically review the plan, identify concerns, and seek human clarification before starting.
Audit Metadata