ln-33-plan-reviewer
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell tools to execute repository-defined commands, such as build, test, and migration scripts, to verify the technical feasibility of implementation plans.
- [DYNAMIC_EXECUTION]: The review framework involves spawning subagents in separate contexts to provide independent perspectives and adversarial challenges during the verification process.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted plan data and user requests, representing an attack surface for indirect injection. 1. Ingestion points: Implementation plans and user requests (SKILL.md). 2. Boundary markers: Absent; no explicit delimiters or ignore-instructions are defined. 3. Capability inventory: Shell execution and subagent spawning (SKILL.md). 4. Sanitization: Absent; no explicit sanitization of plan content before processing is described.
- [PROMPT_INJECTION]: An instruction directs the agent not to invent approval gates from caution, encouraging it to follow explicit project instructions over generalized safety heuristics.
- [EXTERNAL_DOWNLOADS]: The skill searches for and reads official vendor documentation and primary engineering materials from the web to verify external claims and platform semantics.
Audit Metadata