superplan

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to its ability to ingest data from external sources and use it to drive autonomous code execution.
  • Ingestion points: External issue trackers including GitHub Issues, Jira, and Linear are accessed during the 'Gather Context' step in SKILL.md.
  • Boundary markers: The skill instructions do not prescribe specific delimiters or instructions to ignore embedded commands within the fetched ticket data.
  • Capability inventory: The skill possesses significant capabilities, including filesystem modification (Edit, Write) and shell command execution (Bash). It supports autonomous execution via the --yes flag and milestone mode (next M<N>), which bypasses user confirmation prompts.
  • Sanitization: No sanitization or validation of the fetched ticket content is specified before it is processed to generate task instructions.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool for repository management and task execution. The autonomous execution features allow the agent to perform series of file modifications and command executions without individual user approvals.
  • [EXTERNAL_DOWNLOADS]: The skill fetches feature descriptions and acceptance criteria from external project management services. These are well-known services used as intended within the developer workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 12:54 PM
Security Audit — agent-trust-hub — superplan