plan-mode-review

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a robust framework for architectural and code reviews using standard, non-privileged tools (Read, Glob, Grep). Its operations are confined to analyzing the provided project context.
  • [PROMPT_INJECTION]: The skill processes untrusted external data such as source code, pull request descriptions, and implementation plans. This creates an inherent surface for indirect prompt injection (Category 8). This risk is effectively mitigated by the skill's rigid multi-turn protocol, structured phase-based gates, and mandatory human approval checkpoints that prevent the agent from proceeding without explicit user oversight.
  • [COMMAND_EXECUTION]: The skill includes instructions for running standard security and health checks on dependencies using established tools like npm audit and pip-audit. These are well-known development utilities and their use is appropriate for the skill's stated purpose of production readiness review.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:53 PM
Security Audit — agent-trust-hub — plan-mode-review