phased-implement
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes an arbitrary validation command provided via the
--validationcommand-line argument or defined within thevalidationfield of the master plan YAML block. This is a core functionality for verifying implementation phases but represents a command execution vector if the source of the plan is untrusted.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from the repository's source code and external master plan files. This data is used to generate implementation plans and is interpolated into the instructions provided to sub-agents.\n - Ingestion points: The skill reads local files using
GlobandReadtools to generate plans and loads external master plan files provided via the--planargument. It also reads result sentinels written by other agents in thecaptures/directory.\n - Boundary markers: The skill uses Markdown headers and structured sections (e.g.,
## Phase context,## Acceptance criteria) in its prompt templates to delineate context for sub-agents.\n - Capability inventory: The skill executes shell commands via the
Bashtool for git operations,workmuxorchestration, and the user-specified validation commands.\n - Sanitization: No explicit sanitization or validation of the ingested repository content or plan data is mentioned before it is interpolated into prompts or executed as commands.
Audit Metadata