planning-with-files

Warn

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes lifecycle hooks (PreToolUse and Stop) to automate task status reporting and context injection. The Stop hook executes shell and PowerShell scripts with bypassed execution policies, and the PreToolUse hook runs cat commands before tool operations.
  • [DATA_EXFILTRATION]: The session-catchup.py script programmatically accesses the agent's internal session logs stored in the ~/.claude/projects/ directory. It extracts snippets of previous user-assistant messages to recover context, which constitutes exposure of sensitive historical interaction data within the current session.
  • [PROMPT_INJECTION]: The skill introduces an indirect prompt injection surface by reading and injecting content from user-editable files into the system prompt. Specifically, the PreToolUse hook injects the start of task_plan.md before tool calls without the use of boundary markers or sanitization to isolate the file content from instructions.
  • [EXTERNAL_DOWNLOADS]: The skill configuration specifies a source from a non-trusted third-party GitHub repository (OthmanAdi/planning-with-files).
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — planning-with-files