ln-11-plan-reviewer

Warn

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use "Repository-defined commands through the shell" to verify the feasibility of builds, tests, migrations, and scripts. This involves running code or commands specified in the repository being analyzed, which could lead to the execution of malicious scripts if the repository content is untrusted.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates a significant attack surface for indirect prompt injection due to its core functionality of reading and interpreting repository content.
  • Ingestion points: The agent is directed to read "repository instruction files," "Git state," "manifests," and external URLs or proposals referenced in implementation plans (e.g., in Section 3: "Open and inspect any specific document, proposal, issue, or URL").
  • Boundary markers: While the skill provides a structured checklist, it does not mandate the use of delimiters or specific warnings to ignore instructions embedded within the files it reads.
  • Capability inventory: The agent has the capability to execute shell commands and perform web searches based on its findings.
  • Sanitization: There are no instructions to sanitize, escape, or validate the content of the repository files or external URLs before they are processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill authorizes the agent to use "documentation search or the web" to research "Official vendor documentation, specifications, or standards." This involves accessing external, potentially attacker-controlled content to verify claims made in a plan.
  • [DYNAMIC_EXECUTION]: The skill facilitates dynamic execution by instructing the agent to resolve and run commands derived from repository-specific metadata, such as "manifests, lockfiles, configuration, and generated metadata."
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 6, 2026, 04:10 PM
Security Audit — agent-trust-hub — ln-11-plan-reviewer