executing-plans
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and execute instructions from external implementation plans, creating a surface for indirect prompt injection. \n- Ingestion points: External plan files are read from the filesystem during the 'Load and Review Plan' phase. \n- Boundary markers: There are no technical delimiters or markers provided to separate untrusted plan content from the agent's core instructions. \n- Capability inventory: The agent is directed to execute all tasks in the plan, perform file writes (TodoWrite), and run verifications, implying broad system access. \n- Sanitization: Security relies on the agent's ability to 'review critically' and raise concerns with a human partner before beginning implementation.
Audit Metadata