pi-planning-with-files
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages persistent planning state through markdown files (
task_plan.md,findings.md,progress.md) which may ingest untrusted content from the agent's research activities. - Ingestion points: Data enters the agent's context during initialization or tool execution when the skill's hooks read the project's planning files.
- Boundary markers: The skill implements robust structured data framing using
===BEGIN-PWF-DATA===and===END-PWF-DATA===delimiters. In version 3, it adds per-session nonces to these delimiters to further harden the boundary against injection. - Capability inventory: The skill's scripts (
inject-plan.py,skill-hook.sh) utilizesubprocess.runandshto execute its own logic for ledger management and status checks. It does not execute instructions found within the data files. - Sanitization: It includes a built-in SHA-256 attestation mechanism (
attest-plan.sh) that allows users to lock approved plans; the hooks will refuse to inject plan content if the file is modified without approval. Additionally, containment guards ensure that plan resolution cannot be redirected outside the project project root using symlinks. - [DATA_EXFILTRATION]: The skill includes a session recovery script (
session-catchup.py) that reads local agent session records to help restore context. - Exposure: The script accesses local transcripts stored in standard AI agent directories (e.g.,
~/.claude/projects/and~/.codex/sessions/). - No Exfiltration: The skill contains no network functionality, and the documentation explicitly states it has no network upload path. The collected metadata and excerpts are printed strictly for the agent's own use within the local session context.
- Controls: The recovery feature is disabled by default and requires explicit user action via the
--metadataor--replayflags to access host session history.
Audit Metadata