planning-with-files-zh
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes and injects contents from local files (
task_plan.md,findings.md,progress.md) into the agent's context during tool calls and prompt submissions. While the skill implements security measures like SHA-256 attestation and nonce-based framing to verify plan integrity, the processing of potentially untrusted data remains an attack surface. - Ingestion points: Planning files (
task_plan.md, etc.) are read byinject-plan.shandinject-plan.pyand provided to the agent as context. - Boundary markers: The skill uses
===BEGIN-PWF-DATAand===END-PWF-DATAtags with nonces and SHA-256 hashes to frame injected data. - Capability inventory: The skill allows access to
Read,Write,Edit,Bash,Glob, andGreptools. - Sanitization: Implements an attestation system (
attest-plan.sh,attest-plan.ps1) to ensure the planning files have not been modified without authorization. - [DYNAMIC_EXECUTION]: Several PowerShell scripts (
attest-plan.ps1,resolve-plan-dir.ps1,set-active-plan.ps1) use theAdd-Typecmdlet to compile and load C# code at runtime. This is used to implement a 'containment guard' by accessing Win32 APIs (e.g.,GetFinalPathNameByHandleW) to prevent symlink/junction traversal attacks and ensure files remain within the project root. - [COMMAND_EXECUTION]: The skill makes extensive use of local command execution to manage its workflow. This includes the Python scripts
inject-plan.pyandsession-catchup.pyspawning shell processes to run auxiliary scripts likeledger-summary.sh. These operations are performed on local files within the project's.planningdirectory and are part of the core functionality.
Audit Metadata