executing-plans

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes and executes instructions from external files which may contain malicious commands or overrides.
  • Ingestion points: The process begins in 'Step 1: Load and Review Plan' where the agent is instructed to 'Read plan file'. This file serves as the entry point for untrusted data.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to isolate the plan content from the agent's core safety directives, though it does include a 'review critically' instruction.
  • Capability inventory: The skill provides a high degree of autonomy by instructing the agent to 'Follow each step exactly' and 'Run verifications', which involves file system operations and command execution via the agent's available tools.
  • Sanitization: No sanitization, escaping, or schema validation is mentioned for the ingested plan content before the agent begins execution steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:04 AM
Security Audit — agent-trust-hub — executing-plans