planning-agent
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a standard planning and research assistant. It uses platform-provided tools (Task, Read, Bash) within restricted boundaries to analyze code and document implementation strategies.
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests user-provided conversation context to drive sub-agent tasks and file research. However, this is inherent to its primary function and is mitigated by the restricted action space.
- Ingestion points: Conversation context and continuity ledgers (SKILL.md).
- Boundary markers: None explicitly defined for untrusted input processing.
- Capability inventory: Spawning sub-agents via Task, reading codebase files, and executing basic shell commands (ls).
- Sanitization: Input is parsed for requirements but no explicit sanitization of strings used in sub-agent prompts is specified.
Audit Metadata