evo-writing-plans

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted user specifications to generate implementation plans containing executable code and shell commands.
  • Ingestion points: User-provided specifications or requirements for multi-step tasks.
  • Boundary markers: Absent. The skill does not employ delimiters or specific instructions to prevent the agent from obeying malicious instructions embedded within the user requirements.
  • Capability inventory: The generated output includes Python code and shell commands (e.g., git, pytest) intended to be executed by the user or a downstream skill (e.g., evo-executing-plans).
  • Sanitization: Absent. Input requirements are directly interpolated into the structured markdown tasks without validation or escaping.
  • [COMMAND_EXECUTION]: The skill templates and encourages the generation of shell commands for version control and testing operations.
  • Evidence: The plan structure includes specific commands such as git add, git commit, and pytest with paths and parameters derived from the generated plan content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:44 AM
Security Audit — agent-trust-hub — evo-writing-plans