executing-plans

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and execute instructions from external plan files, which presents a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (Step 1: Load and Review Plan).
  • Boundary markers: Absent; there are no instructions to differentiate between plan data and embedded commands.
  • Capability inventory: The skill coordinates implementation tasks that typically involve file system access and shell command execution.
  • Sanitization: Absent; the skill does not specify any validation or sanitization for the plan content before following the steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:35 AM
Security Audit — agent-trust-hub — executing-plans