planning-with-files-es
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local Markdown files (
task_plan.md,findings.md,progress.md) and injects it into the agent's prompt during tool use and prompt submission. - Ingestion points: Planning files are read by
scripts/inject-plan.shandscripts/inject-plan.py. Thefindings.mdfile is explicitly intended for storing research results from external tools. - Boundary markers: The skill implements a robust mitigation using
===BEGIN-PWF-DATA===and===END-PWF-DATA===delimiters paired with content-derived nonces. - Capability inventory: The agent is granted
Read,Write,Edit,Bash,Glob, andGreptools, providing significant control over the project environment. - Sanitization: The skill performs character escaping (backslashes, quotes, and control characters) when formatting data for model injection.
- [COMMAND_EXECUTION]: The skill executes multiple internal shell and Python scripts to manage its state and generate prompt context.
- Evidence: Scripts such as
scripts/inject-plan.pyusesubprocess.run()to call internal helpers likeledger-summary.sh. - Mitigation: The scripts include advanced security checks, such as
is_within_rootandsafe_snapshot(usingO_NOFOLLOWand descriptor-based verification), to prevent directory traversal and symlink-based attacks. - [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes platform lifecycle hooks to execute shell commands at runtime, which modifies the agent's context dynamically.
- Evidence:
SKILL.mddefinesUserPromptSubmit,PreToolUse,PostToolUse,Stop, andPreCompacthooks that trigger theskill-hook.shdispatcher. - [DATA_EXPOSURE]: The
scripts/session-catchup.pyscript accesses local session metadata and history logs from~/.claude/projects/and~/.codex/sessions. - Mitigation: Data retrieval is restricted to sessions matching the current project path, and the output of transcript excerpts is disabled by default, requiring an explicit
--replayflag.
Audit Metadata