planning-with-files-zh

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and injects contents from local files (task_plan.md, findings.md, progress.md) into the agent's context during tool calls and prompt submissions. While the skill implements security measures like SHA-256 attestation and nonce-based framing to verify plan integrity, the processing of potentially untrusted data remains an attack surface.
  • Ingestion points: Planning files (task_plan.md, etc.) are read by inject-plan.sh and inject-plan.py and provided to the agent as context.
  • Boundary markers: The skill uses ===BEGIN-PWF-DATA and ===END-PWF-DATA tags with nonces and SHA-256 hashes to frame injected data.
  • Capability inventory: The skill allows access to Read, Write, Edit, Bash, Glob, and Grep tools.
  • Sanitization: Implements an attestation system (attest-plan.sh, attest-plan.ps1) to ensure the planning files have not been modified without authorization.
  • [DYNAMIC_EXECUTION]: Several PowerShell scripts (attest-plan.ps1, resolve-plan-dir.ps1, set-active-plan.ps1) use the Add-Type cmdlet to compile and load C# code at runtime. This is used to implement a 'containment guard' by accessing Win32 APIs (e.g., GetFinalPathNameByHandleW) to prevent symlink/junction traversal attacks and ensure files remain within the project root.
  • [COMMAND_EXECUTION]: The skill makes extensive use of local command execution to manage its workflow. This includes the Python scripts inject-plan.py and session-catchup.py spawning shell processes to run auxiliary scripts like ledger-summary.sh. These operations are performed on local files within the project's .planning directory and are part of the core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:49 PM
Security Audit — agent-trust-hub — planning-with-files-zh