ln-11-plan-reviewer

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a highly structured and defensive framework for reviewing code changes without execution. It promotes security best practices by including explicit checks for trust boundaries, authentication, and sensitive data handling within the reviewed plans.
  • [COMMAND_EXECUTION]: The skill permits the use of shell tools and repository-defined commands (e.g., build and test scripts) to verify the feasibility of proposed changes. This is a standard capability for development-oriented agents. The risk is mitigated by explicit instructions to maintain a read-only posture and to mark execution as unverified when direct evidence is unavailable.
  • [PROMPT_INJECTION]: The skill processes external data from implementation plans and web-based documentation, creating an indirect prompt injection surface. This is managed through a rigorous, checklist-driven workflow that requires grounding all claims in the repository's source of truth.
  • Ingestion points: Implementation plans provided as user input, repository-resident files (e.g., AGENTS.md), and external documentation retrieved via search tools.
  • Boundary markers: The skill employs a structured checklist with a 'Definition of Done' and a formal output schema to maintain agent focus.
  • Capability inventory: The agent is granted access to file system read operations, shell command execution (git, npm, pip, etc.), and the ability to spawn independent subagents.
  • Sanitization: No explicit string sanitization or escaping of external content is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 07:43 PM
Security Audit — agent-trust-hub — ln-11-plan-reviewer