plan-arbiter

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes plan data from various potentially untrusted sources including PR descriptions, comments, transcripts, and external links. If these plans contain hidden instructions, the agent may inadvertently follow them when merging the plans or transitioning to the implementation phase.
  • Ingestion points: references/builder-upstream.md specifies that sources include "pasted text, local files, session IDs, transcript paths, PRs, comments, visual-plan links, or chat history."
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the source plans being normalized and merged.
  • Capability inventory: The skill allows for the automated transition to implementation ("proceed with the selected plan after reporting the decision briefly") and has the capability to read repository files, docs, and external systems for cross-verification.
  • Sanitization: No mention is made of sanitizing, escaping, or validating the content of the plans before they are incorporated into the final executable direction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:00 AM
Security Audit — agent-trust-hub — plan-arbiter