plannotator-tui
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
plannotator-tuiandherdrCLI tools to manage project documentation reviews within specialized UI panes. These commands are essential to the skill's operation and belong to the author's tool suite.- [INDIRECT_PROMPT_INJECTION]: The skill processes external feedback provided by humans, which is then re-ingested into the agent's context. - Ingestion points: Feedback is received as the next user message after a document is opened via
plannotator-tui. - Boundary markers: There are no explicit delimiters or warnings to ignore embedded instructions within the feedback stream.
- Capability inventory: The agent possesses file system access (writing documents) and shell command execution capabilities (
herdr,plannotator-tui,printf). - Sanitization: There is no mention of sanitization, validation, or escaping of the feedback before the agent is instructed to 'Address every item'.
Audit Metadata