planning-with-files-es

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local Markdown files (task_plan.md, findings.md, progress.md) and injects it into the agent's prompt during tool use and prompt submission.
  • Ingestion points: Planning files are read by scripts/inject-plan.sh and scripts/inject-plan.py. The findings.md file is explicitly intended for storing research results from external tools.
  • Boundary markers: The skill implements a robust mitigation using ===BEGIN-PWF-DATA=== and ===END-PWF-DATA=== delimiters paired with content-derived nonces.
  • Capability inventory: The agent is granted Read, Write, Edit, Bash, Glob, and Grep tools, providing significant control over the project environment.
  • Sanitization: The skill performs character escaping (backslashes, quotes, and control characters) when formatting data for model injection.
  • [COMMAND_EXECUTION]: The skill executes multiple internal shell and Python scripts to manage its state and generate prompt context.
  • Evidence: Scripts such as scripts/inject-plan.py use subprocess.run() to call internal helpers like ledger-summary.sh.
  • Mitigation: The scripts include advanced security checks, such as is_within_root and safe_snapshot (using O_NOFOLLOW and descriptor-based verification), to prevent directory traversal and symlink-based attacks.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes platform lifecycle hooks to execute shell commands at runtime, which modifies the agent's context dynamically.
  • Evidence: SKILL.md defines UserPromptSubmit, PreToolUse, PostToolUse, Stop, and PreCompact hooks that trigger the skill-hook.sh dispatcher.
  • [DATA_EXPOSURE]: The scripts/session-catchup.py script accesses local session metadata and history logs from ~/.claude/projects/ and ~/.codex/sessions.
  • Mitigation: Data retrieval is restricted to sessions matching the current project path, and the output of transcript excerpts is disabled by default, requiring an explicit --replay flag.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:28 PM
Security Audit — agent-trust-hub — planning-with-files-es