visual-plan

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with the official Agent-Native infrastructure (plan.agent-native.com) and utilizes scoped NPM packages (@agent-native/skills, @agent-native/core) for installation and local bridge operations. These actions are consistent with the skill's primary purpose and originate from the vendor's own services.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted source material (user-pasted text, repository files, and referenced plans) at its primary ingestion points in SKILL.md. Boundary markers for the source plan text are not explicitly defined. The capability inventory includes network operations via the Plan MCP tools and local file creation/modification in local-files mode. While explicit automated sanitization is not described, the skill enforces a read-only protocol where no source code edits are permitted until a human reviewer explicitly approves the final visual plan document, serving as a critical safety boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 03:57 PM
Security Audit — agent-trust-hub — visual-plan