skills/kensaurus/skills/plan-antislop/Gen Agent Trust Hub

plan-antislop

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from a codebase, including user-facing prose, code comments, and UI definitions. This creates a surface for indirect prompt injection where malicious instructions embedded in the audited files could attempt to influence the agent's behavior during the audit process.
  • Ingestion points: The skill instructions direct the agent to scan all user-facing strings, marketing copy, READMEs, microcopy, error messages, and code comments (SKILL.md).
  • Boundary markers: The skill implements a mitigation by instructing the agent to "Quote the minimum needed to identify the tell — never paste whole files," which limits the amount of untrusted content brought into the agent's active context.
  • Capability inventory: The skill is restricted to auditing and planning. It explicitly forbids automated rewrites or code execution ("Audit & plan only — no rewrites until each phase is approved").
  • Sanitization: There are no explicit instructions for sanitizing or escaping the untrusted content before it is interpolated into the final markdown report (plan-antislop.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — plan-antislop