executing-plans
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to "Follow each step exactly" from a plan file provided in the environment.
- Ingestion points: The skill starts by reading a plan file in Step 1 of the implementation process.
- Boundary markers: There are no instructions to use delimiters or ignore potential instruction overrides within the external plan content.
- Capability inventory: The skill empowers the agent to perform a wide range of actions across all scripts, including task execution, code modification, and running verification scripts.
- Sanitization: The skill lacks any requirement to sanitize or validate the content of the plan file before execution.
Audit Metadata