skills/pokanop/ai/plan-retrospective/Gen Agent Trust Hub

plan-retrospective

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user-controlled data from project files which could contain hidden instructions (Indirect Prompt Injection). * Ingestion points: plans//prd.md, plans//tasks.md, and plans//decisions.md. * Boundary markers: Absent. * Capability inventory: Reading local files, writing retro.md, and moving project directories. * Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill requests directory move (mv) operations to relocate project folders to plans/archive/. This is a core functionality of the skill and is gated by mandatory user confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 08:33 PM
Security Audit — agent-trust-hub — plan-retrospective