planning-with-files-de
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads project files and injects their content into the AI's context window. This creates a surface for indirect prompt injection if the agent writes untrusted data (e.g., from web results) into these files.
- Ingestion points:
task_plan.md,findings.md,progress.md, and Claude Code session logs in~/.claude/projects/(viasession-catchup.py). - Boundary markers: The skill implements robust framing using
===BEGIN-PWF-DATA ... ===and===END-PWF-DATA ... ===delimiters with nonces and SHA256 hashes. It includes explicit instructions to the AI to ignore any embedded instructions within the data. - Capability inventory: The agent is granted tools like
Bash,Write, andEdit, providing significant system access. - Sanitization: Implements 'Plan Attestation' (hashing) to detect unauthorized file changes, path containment checks to prevent directory traversal, and session-isolation sentinels.
- [DATA_EXFILTRATION]: The
session-catchup.pyscript accesses sensitive local application data by reading Claude Code transcripts in~/.claude/projects/. This access is restricted via project-path normalization and filtering to ensure transcripts are only recovered for the active project, and it is framed as an explicit, user-invocable recovery tool. - [COMMAND_EXECUTION]: The skill relies on a chain of local shell and Python scripts (e.g.,
skill-hook.sh,inject-plan.sh) executed through lifecycle hooks to perform environment resolution and context generation. - [DYNAMIC_EXECUTION]: Scripts like
inject-plan.pyusesubprocess.runto call summary utilities and utilize low-level system calls viactypeson Windows to perform secure path validation and prevent symlink-based attacks during file ingestion.
Audit Metadata