skills/mvdmakesthings/skills/plan-qa/Gen Agent Trust Hub

plan-qa

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands like 'ls', 'cat', and 'git' to detect project configuration and testing frameworks for context gathering.- [COMMAND_EXECUTION]: Performs a network upload via 'curl' using a signed URL obtained from the Linear MCP plugin to attach the generated test plan to the corresponding issue.- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Ingestion points: Linear issue descriptions and acceptance criteria via 'mcp__plugin_linear_linear__get_issue' (Phase 0.1). Boundary markers: Absent (data is interpolated directly into a markdown template). Capability inventory: Local file access ('ls', 'cat'), git history ('git log'), and Linear attachment mutation. Sanitization: Includes a mandatory human-in-the-loop approval step in Phase 3 where the developer must review and approve the draft before any external mutation occurs.- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill maintains a transparent operation flow with explicit user sign-off for its primary actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 02:27 PM
Security Audit — agent-trust-hub — plan-qa