executing-plans
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because its primary function is to ingest and follow instructions from an external plan file.
- Ingestion points: The skill reads implementation plan files in SKILL.md (Step 1).
- Boundary markers: There are no defined delimiters or instructions to ignore embedded prompts within the plan content.
- Capability inventory: The skill permits task execution and verification runs in SKILL.md (Step 2), which typically involve code modifications or shell command execution.
- Sanitization: No sanitization or validation of the plan's contents is performed before the agent begins execution.
Audit Metadata