skills/microsoft/hve-core/rpi-plan/Gen Agent Trust Hub

rpi-plan

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest research artifacts and user requirements to generate structured implementation plans. This workflow creates a surface where instructions embedded in input data could potentially influence the planning logic.
  • Ingestion points: Research artifacts are read from the .copilot-tracking/research/ directory as specified in SKILL.md.
  • Boundary markers: The instructions do not define explicit boundary markers or 'ignore instructions' headers for the ingested research content.
  • Capability inventory: The skill has the capability to write files to the .copilot-tracking/ directory and invoke internal subagents like the Researcher and Plan Validator.
  • Sanitization: No explicit sanitization or filtering of input research data is documented before processing.
  • Controlled File Access: The skill strictly limits its write operations to designated tracking directories, which minimizes the risk of unintended modification of core project files.
  • Evidence: Constraints in SKILL.md limit writing to specific subdirectories within .copilot-tracking/ such as plans, logs, details, and research.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 03:39 PM
Security Audit — agent-trust-hub — rpi-plan