skills/mouadja02/skills/writing-plans/Gen Agent Trust Hub

writing-plans

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured guidance for the AI to decompose requirements into actionable, testable tasks. It includes templates for testing (pytest) and version control (git) to be used in the generated plan, but no commands are executed by the skill itself.
  • [SAFE]: All external references point to legitimate source code repositories on GitHub for attribution and documentation purposes. No automated downloads or remote code executions are initiated.
  • [PROMPT_INJECTION]: The skill processes technical specifications as input, which constitutes an indirect prompt injection surface. The risk is minimized because the skill only generates documentation (Markdown plans) and does not execute the content it processes.
  • Ingestion points: Reads project specifications or requirements via file paths.
  • Boundary markers: None explicitly defined to isolate the input spec from planning instructions.
  • Capability inventory: The skill's function is text generation; it does not invoke shell commands, file writes, or network operations.
  • Sanitization: No specific sanitization of input specification content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:02 PM
Security Audit — agent-trust-hub — writing-plans