skills/poteto/noodle/plan/Gen Agent Trust Hub

plan

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses the find-skills tool to discover and install new agent skills. In 'Autonomous Session Mode,' these skills are installed and invoked without human-in-the-loop review, which could lead to the execution of unverified or malicious code discovered at runtime.
  • [EXTERNAL_DOWNLOADS]: The planning workflow involves downloading and installing project-local skills from external sources via the find-skills mechanism. The lack of verification for these external components in autonomous mode presents a potential supply chain risk.
  • [COMMAND_EXECUTION]: The skill executes shell commands to signal session status via the noodle utility. The use of environment variables and dynamic plan paths in these commands could be exploited if inputs are not properly sanitized.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which could contain hidden instructions intended to influence the planning output. 1. Ingestion points: brain/principles.md, codebase content analyzed by Explore subagents, and instructions within discovered domain skills. 2. Boundary markers: The skill lacks explicit boundary markers or directives to isolate ingested data from the planning logic. 3. Capability inventory: File system writes, subagent spawning, and autonomous skill installation. 4. Sanitization: No explicit sanitization or validation of ingested context is performed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 03:00 AM