plan-work

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because its core process requires reading untrusted repository content (instructions, docs, code) to inform the creation of planning artifacts.
  • Ingestion points: SKILL.md (Step 1) requires reading "repo-local instructions, current docs, relevant code, and existing Plans or Roadmaps".
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to distinguish between the skill's instructions and the content being analyzed.
  • Capability inventory: The skill specifies creating and modifying markdown files in the repository (e.g., in the plans/ and docs/ directories).
  • Sanitization: No input validation or sanitization of the content extracted from the repository is defined.
  • [NO_CODE]: The skill consists entirely of natural language instructions and configuration files (YAML, TOML) without any executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 03:47 AM
Security Audit — agent-trust-hub — plan-work