planning-with-files-zht

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a persistent planning mechanism that reads from local files (task_plan.md, findings.md, progress.md) and session history. This represents an indirect prompt injection attack surface where untrusted data could influence the agent's behavior.
  • Ingestion points: The skill ingests data from task_plan.md, findings.md, progress.md, and Claude Code session logs located in ~/.claude/projects/ and ~/.claude/sessions/.
  • Boundary markers: The skill employs robust boundary markers using the ===BEGIN-PWF-DATA and ===END-PWF-DATA format. These markers include a unique nonce, byte count, and SHA-256 hash for each data block to prevent delimiter confusion attacks.
  • Capability inventory: The skill is configured with Read, Write, Edit, Bash, Glob, and Grep tools.
  • Sanitization: Data is sanitized through strict nonce-based framing, and the agent is explicitly instructed to treat the injected content as data-only and ignore any instruction-like text within the plan data.
  • [COMMAND_EXECUTION]: Several scripts (skill-hook.sh, inject-plan.sh, attest-plan.sh) perform command execution for system tasks such as computing file hashes (sha256sum), creating temporary files (mktemp), and managing file permissions. These operations are performed on local files and are essential for the skill's integrity and security features.
  • [DYNAMIC_EXECUTION]: The PowerShell scripts (attest-plan.ps1, resolve-plan-dir.ps1) use the Add-Type cmdlet to define C# classes that call native Windows APIs (CreateFileW, GetFinalPathNameByHandleW). This is used to implement secure file access patterns that prevent symlink and junction-based path traversal attacks, which is a defensive best practice in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:28 PM
Security Audit — agent-trust-hub — planning-with-files-zht