skills/mastra-ai/mastra/ralph-plan/Gen Agent Trust Hub

ralph-plan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as a structured guide for an agent to collaborate with users on architectural and task planning. It uses a clear XML-like format to organize background context, setup steps, task lists, and testing procedures. The primary focus is organizational clarity and codebase exploration for standard developer tasks. No malicious patterns, persistence mechanisms, or unauthorized privilege attempts were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input to generate instructions for a downstream agent, creating a theoretical injection surface. However, this is assessed as safe based on the following: 1. Ingestion points: User dialogue provided during the conversational planning steps defined in SKILL.md. 2. Boundary markers: The assistant is instructed to use XML-like tags (, , etc.) which provide structural delimiters for the generated content. 3. Capability inventory: The skill itself consists solely of text-based instructions and contains no scripts, executable code, or direct tool definitions. 4. Sanitization: The instructions specifically advise the agent to avoid double quotes and backticks in the output to ensure copy-paste stability, which acts as a basic form of character filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:10 AM
Security Audit — agent-trust-hub — ralph-plan