taku-plan
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No network activity or external downloads. The skill only interacts with local files such as
DESIGN.mdandPLAN.mdand relies on internal reference documents within the skill folder. - [SAFE]: No command execution or remote code patterns. The skill is composed of markdown instructions and templates for an LLM to follow, with no shell scripts or executable code provided.
- [SAFE]: No obfuscation detected. All content is provided in plain-text markdown without encoding, zero-width characters, or hidden strings.
- [PROMPT_INJECTION]: The skill uses natural instructional language and established rule labels (e.g.,
[IRON LAW]) to guide behavior without attempting to bypass safety filters or extract system prompts. - [DATA_EXFILTRATION]: No exfiltration risks. The skill has no capability to transmit data externally, and it does not access sensitive system paths or credentials.
- [SAFE]: Indirect Prompt Injection surface is minimal. While the skill ingests user-controlled data (
DESIGN.md), its capabilities are restricted to generating markdown text, posing no significant execution risk to the environment.
Audit Metadata