writing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a transformation layer for untrusted user specifications, converting them into actionable implementation plans for downstream autonomous skills. This creates a vulnerability surface where malicious instructions in a specification could be propagated into the final plan. \n- Ingestion points: Processes user-provided software requirements and project specifications as the primary input for plan generation. \n- Boundary markers: Includes a mandatory 'Self-Review' checklist and a 'Plan Document Reviewer' subagent prompt template to verify plan alignment and completeness before execution. \n- Capability inventory: The skill writes markdown files to the local filesystem and prepares tasks containing shell commands and code snippets for execution by other skills like 'superpowers:subagent-driven-development'. \n- Sanitization: Relies on verification prompts and human-in-the-loop decision points during execution handoff rather than programmatic input filtering or sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — writing-plans