afk-phase-planning

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its workflow of transforming untrusted data into new artifacts.
  • Ingestion points: The skill reads external 'upstream artifacts' such as briefs, specs, and refined drafts, along with general codebase context into the agent's workspace (SKILL.md, Workflow Step 1).
  • Boundary markers: There are no instructions provided to use delimiters or 'ignore embedded instructions' warnings when the agent processes these external data sources.
  • Capability inventory: The agent has the capability to write the resulting phase plan as a new markdown file within the repository's file system (SKILL.md, Workflow Step 5).
  • Sanitization: The skill does not include any steps for validating or sanitizing the content of the source artifacts before they are integrated into the final phase plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 09:41 PM
Security Audit — agent-trust-hub — afk-phase-planning