skills/pooyagolchian/specforge/plan/Gen Agent Trust Hub

plan

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate technical planning tasks, reading project context and writing markdown design documents. No evidence of obfuscation, exfiltration, or malicious command execution was found.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by reading untrusted data from files such as spec.md. It lacks boundary markers and sanitization for this input (Ingestion points: spec.md, constitution.md, tech-environment.md in SKILL.md). However, because the toolset is limited to local file system operations (Read, Write, Edit, Glob, Grep) and has no network or execution capabilities, the vulnerability does not lead to significant escalation paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 11:43 AM
Security Audit — agent-trust-hub — plan