blueprint
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONNO_CODEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to utilize standard command-line tools, including
gitand the GitHub CLI (gh), to verify authentication, branch status, and repository metadata. This is part of the core functionality for generating project roadmaps. - [NO_CODE]: The skill consists exclusively of Markdown-formatted instructions. It does not include embedded scripts, binary files, or external package dependencies that would execute code on the host system.
- [PROMPT_INJECTION]: The skill processes untrusted project data (files, plans, structure) to generate roadmaps, creating an attack surface for indirect prompt injection.
- Ingestion points: The agent reads project structure, existing plans, and memory files in the 'Research' phase (SKILL.md).
- Boundary markers: No explicit delimiters or warnings are used to differentiate project data from agent instructions.
- Capability inventory: The agent has file system write access to create new markdown files in the
plans/directory. - Sanitization: No escaping or filtering of external content is described before interpolation into the agent context.
- [SAFE]: No malicious patterns such as credential exfiltration, persistence, or obfuscation were detected. The skill's behavior is consistent with its stated purpose as a planning and documentation generator.
Audit Metadata