plt-fill-template
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches manifest and template files from the author's GitHub repository (
product-on-purpose/product-lifecycle-templates) when the local library is incomplete. These downloads target the official vendor repository and are used to retrieve the document bundles necessary for the skill's primary function. - [COMMAND_EXECUTION]: The skill instructions direct the agent to run local Python scripts (
tools/strip-template.pyandtools/validate-fill.py) distributed with the skill. These tools perform template post-processing, such as removing guidance comments and verifying structural integrity, which is a standard part of the document generation workflow. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by ingesting and processing template files that contain natural language instructions. While the templates include boundary markers and guidance for the agent, the process of filling placeholders with potentially untrusted external data could lead to instruction override.
- Ingestion points: Manifest and template files (
.md,.json) loaded from the local filesystem or the vendor repository. - Boundary markers: Templates use specific HTML comments (
WHAT,WHY,ASK,GOOD,WEAK,TRAP) to separate instructions from content. - Capability inventory: Capability to execute local Python scripts and perform network requests to fetch templates.
- Sanitization: The included
validate-fill.pytool provides a check for placeholders and metadata, though it focuses on structure rather than content safety.
Audit Metadata