executing-plans
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. Ingestion points: The skill reads external plan files to obtain instructions for implementation tasks (SKILL.md: Step 1). Boundary markers: The instructions do not specify any delimiters or safety markers to isolate the plan content from the agent's core instructions, relying instead on manual critical review. Capability inventory: The skill grants the agent the ability to execute any task defined within the plan, run verifications, and call other development sub-skills (SKILL.md: Step 2 and 3). Sanitization: There are no explicit instructions for validating, escaping, or filtering the contents of the loaded plan files before the agent follows their instructions.
Audit Metadata