executing-plans
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes 'plan files' from the workspace, creating an indirect prompt injection surface where external data influences agent behavior. \n- Ingestion points: Step 1.1 (Read plan file). \n- Boundary markers: No structural delimiters are specified; instead, the skill relies on instructional boundaries and human confirmation. \n- Capability inventory: Coordinates implementation tasks which typically involve code modification and command execution (Step 2). \n- Sanitization: Addressed through mandatory critical review (Step 1.2), partner consultation for concerns (Step 1.3), and strict 'stop and ask' protocols for blockers or unclear instructions.
Audit Metadata