writing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a transformation layer for untrusted user specifications, converting them into actionable implementation plans for downstream autonomous skills. This creates a vulnerability surface where malicious instructions in a specification could be propagated into the final plan. \n- Ingestion points: Processes user-provided software requirements and project specifications as the primary input for plan generation. \n- Boundary markers: Includes a mandatory 'Self-Review' checklist and a 'Plan Document Reviewer' subagent prompt template to verify plan alignment and completeness before execution. \n- Capability inventory: The skill writes markdown files to the local filesystem and prepares tasks containing shell commands and code snippets for execution by other skills like 'superpowers:subagent-driven-development'. \n- Sanitization: Relies on verification prompts and human-in-the-loop decision points during execution handoff rather than programmatic input filtering or sanitization.
Audit Metadata