plan

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and process external, untrusted data from tickets and product context, creating a surface for potential instruction injection.
  • Ingestion points: External tickets, product context, and the AGENTS.md file referenced in the Process section.
  • Boundary markers: The skill does not provide instructions for using boundary markers or explicitly ignoring commands found within the ingested data.
  • Capability inventory: The skill generates markdown plans that act as direct instructions for subsequent implementation and execution tasks.
  • Sanitization: No validation or sanitization process is defined for the content retrieved from external sources before it influences the plan generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:42 PM
Security Audit — agent-trust-hub — plan