executing-plans

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because its primary function is to ingest and follow instructions from an external plan file.
  • Ingestion points: The skill reads implementation plan files in SKILL.md (Step 1).
  • Boundary markers: There are no defined delimiters or instructions to ignore embedded prompts within the plan content.
  • Capability inventory: The skill permits task execution and verification runs in SKILL.md (Step 2), which typically involve code modifications or shell command execution.
  • Sanitization: No sanitization or validation of the plan's contents is performed before the agent begins execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:39 AM
Security Audit — agent-trust-hub — executing-plans