plan-antislop
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from a codebase, including user-facing prose, code comments, and UI definitions. This creates a surface for indirect prompt injection where malicious instructions embedded in the audited files could attempt to influence the agent's behavior during the audit process.
- Ingestion points: The skill instructions direct the agent to scan all user-facing strings, marketing copy, READMEs, microcopy, error messages, and code comments (SKILL.md).
- Boundary markers: The skill implements a mitigation by instructing the agent to "Quote the minimum needed to identify the tell — never paste whole files," which limits the amount of untrusted content brought into the agent's active context.
- Capability inventory: The skill is restricted to auditing and planning. It explicitly forbids automated rewrites or code execution ("Audit & plan only — no rewrites until each phase is approved").
- Sanitization: There are no explicit instructions for sanitizing or escaping the untrusted content before it is interpolated into the final markdown report (
plan-antislop.md).
Audit Metadata