afk-phase-planning
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its workflow of transforming untrusted data into new artifacts.
- Ingestion points: The skill reads external 'upstream artifacts' such as briefs, specs, and refined drafts, along with general codebase context into the agent's workspace (SKILL.md, Workflow Step 1).
- Boundary markers: There are no instructions provided to use delimiters or 'ignore embedded instructions' warnings when the agent processes these external data sources.
- Capability inventory: The agent has the capability to write the resulting phase plan as a new markdown file within the repository's file system (SKILL.md, Workflow Step 5).
- Sanitization: The skill does not include any steps for validating or sanitizing the content of the source artifacts before they are integrated into the final phase plan.
Audit Metadata