plan-input-validation
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a structured prompt for an AI agent to perform security audits. It explicitly instructs the agent to 'Audit & plan only' and 'Change nothing until approved,' which prevents unauthorized modifications to the codebase.
- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected. The instructions are focused on defensive security engineering and application hardening.
- [SAFE]: The skill mentions a future-dated or hypothetical CVE (CVE-2026-41432) as an illustrative example of a common vulnerability pattern (empty signing secrets), which does not present a security risk to the user.
- [SAFE]: There are no remote code executions, package installations, or unauthorized network operations defined within the skill.
Audit Metadata