planning-with-files-de

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads project files and injects their content into the AI's context window. This creates a surface for indirect prompt injection if the agent writes untrusted data (e.g., from web results) into these files.
  • Ingestion points: task_plan.md, findings.md, progress.md, and Claude Code session logs in ~/.claude/projects/ (via session-catchup.py).
  • Boundary markers: The skill implements robust framing using ===BEGIN-PWF-DATA ... === and ===END-PWF-DATA ... === delimiters with nonces and SHA256 hashes. It includes explicit instructions to the AI to ignore any embedded instructions within the data.
  • Capability inventory: The agent is granted tools like Bash, Write, and Edit, providing significant system access.
  • Sanitization: Implements 'Plan Attestation' (hashing) to detect unauthorized file changes, path containment checks to prevent directory traversal, and session-isolation sentinels.
  • [DATA_EXFILTRATION]: The session-catchup.py script accesses sensitive local application data by reading Claude Code transcripts in ~/.claude/projects/. This access is restricted via project-path normalization and filtering to ensure transcripts are only recovered for the active project, and it is framed as an explicit, user-invocable recovery tool.
  • [COMMAND_EXECUTION]: The skill relies on a chain of local shell and Python scripts (e.g., skill-hook.sh, inject-plan.sh) executed through lifecycle hooks to perform environment resolution and context generation.
  • [DYNAMIC_EXECUTION]: Scripts like inject-plan.py use subprocess.run to call summary utilities and utilize low-level system calls via ctypes on Windows to perform secure path validation and prevent symlink-based attacks during file ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:28 PM
Security Audit — agent-trust-hub — planning-with-files-de