plan-ceo-review
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes local gstack utility binaries and standard git/gh commands to audit the repository, determine target branches, and manage internal session state.
- [DATA_EXFILTRATION]: Collects and transmits metadata (usage, duration, and outcomes) via a local telemetry script. The skill includes a clear user disclosure and consent mechanism to manage data sharing preferences.
- [PROMPT_INJECTION]: Dispatches an 'Agent' subagent with a specialized prompt to perform a rigorous review of the proposed plan, checking for clarity and consistency.
- [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface as part of its auditing process:
- Ingestion points: Ingests project-specific data from
CLAUDE.md,TODOS.md, and code grep results. - Boundary markers: Lacks explicit delimiters or 'ignore' instructions when interpolating untrusted file content into analysis prompts.
- Capability inventory: Possesses shell execution (
Bash), interactive questioning (AskUserQuestion), and subagent spawning capabilities. - Sanitization: Does not perform validation or sanitization on the content extracted from the local repository before processing.
Audit Metadata