technical-launch-planner
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill primarily consists of informational markdown files and interactive planning scripts. No malicious patterns, obfuscation, or unauthorized data access were detected.
- [COMMAND_EXECUTION]: The skill includes several utility scripts (
assess_launch_tier.sh,generate_launch_plan.sh,validate_readiness.sh) intended for local use. These scripts use standard interactive shell commands to collect information from the user and generate reports. - [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through its interactive scripts which could be leveraged if untrusted input is processed by a downstream agent.
- Ingestion points: User input captured via
readcommands inscripts/generate_launch_plan.sh(fields like PRODUCT_NAME and DESCRIPTION). - Boundary markers: Absent; user-provided strings are interpolated directly into markdown templates.
- Capability inventory: The skill writes generated content to local files using the
catcommand with output redirection. - Sanitization: No input validation or sanitization is performed on the user-supplied strings before they are written to the output file.
- Ingestion points: User input captured via
Audit Metadata