executing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external implementation plans which serves as a potential vector for indirect prompt injection if the plan contains malicious instructions.
  • Ingestion points: The skill reads an implementation plan file in Step 1.2.
  • Boundary markers: Instructions require a critical review of the plan (Step 1.3) and mandate stopping immediately if instructions are unclear or suspicious.
  • Capability inventory: Executes implementation tasks, manages git worktrees, and calls subsequent verification skills.
  • Sanitization: Relies on the agent's critical analysis step and mandatory human partner checkpoints to validate the plan's contents before execution.
  • [EXTERNAL_DOWNLOADS]: The skill references external subagent tools such as Google's Gemini CLI and GitHub Copilot CLI as recommended capabilities for the environment. These are documented as platform references for the user rather than automated downloads or remote code executions performed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:13 PM
Security Audit — agent-trust-hub — executing-plans