rpi-plan
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill is designed to analyze external research, user documents, and evidence, which creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the source material. The skill includes a 'Constraints' section that explicitly directs the agent to treat all external content as data and to ignore any authority claims or instructions contained within it. (1) Ingestion points: The skill gathers information from user-pointed documents and research evidence as described in the flow defined in SKILL.md. (2) Boundary markers: The skill utilizes instructional constraints to establish operational boundaries when processing external data. (3) Capability inventory: The agent is capable of writing implementation plans to the workspace tracking directory and invoking sub-agents for specialized planning tasks. (4) Sanitization: The instructions mandate that the agent disregard any embedded commands in source data to ensure the planning process remains evidence-based.
Audit Metadata