plan-ceo-review

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted materials such as product plans and repository data. It does not include specific guardrails to prevent instructions embedded within those materials from overriding the agent's behavior.
  • Ingestion points: SKILL.md (Workflow step 1 involves reading plans, repo data, and constraints).
  • Boundary markers: Absent; there are no delimiters or instructions to ignore embedded commands in the source materials.
  • Capability inventory: The skill performs reasoning on ingested data to produce structured plans and risk tables defined in references/output-template.md.
  • Sanitization: Absent; no logic is provided to filter or validate the content of the documents being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:25 AM
Security Audit — agent-trust-hub — plan-ceo-review