autoplan
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages the Bash tool to manage project state, query git metadata, and run local utility scripts provided by the vendor in the gstack directory. This includes detecting git remotes and interacting with CLI tools like gh and glab.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface where external plan data is processed and sent to sub-agents. Ingestion points: Plan files and design documents read during Phase 0 and Phase 1. Boundary markers: Present; the skill provides specific instructions to the Codex sub-agent to ignore skill definitions (SKILL.md) on disk to prevent instruction confusion. Capability inventory: Full access to tools like Bash, Read, Write, Edit, and WebSearch across orchestrated scripts. Sanitization: The skill does not explicitly sanitize the plan content before interpolation, but it uses it within defined analytical frameworks.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the Codex service via a local CLI tool and interacts with git remote endpoints (GitHub/GitLab) for repository context, which involves communication with external infrastructure appropriate for the skill's development workflow purpose.
Audit Metadata