writing-plans

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified. The skill ingests untrusted specifications (input) to generate implementation plans. Malicious content in the input could theoretically influence the generated tasks, which are subsequently executed by other system components. * Ingestion points: The input field in SKILL.md is used to receive external specifications or requirements. * Boundary markers: There are no explicit delimiters or boundary instructions used to isolate the untrusted input from the skill's core instructions. * Capability inventory: While the skill itself only generates text, it references and hands off tasks to other capabilities like superpowers:executing-plans, which have shell execution and file system access. * Sanitization: No validation or sanitization of the input specification is mentioned or performed.
  • [NO_CODE]: The skill consists entirely of markdown instructions and prompt templates. It does not contain executable scripts, binaries, or automated code installation procedures, which minimizes its direct attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 07:08 AM
Security Audit — agent-trust-hub — writing-plans