executing-plans
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to load and execute tasks from external plan files, which introduces a risk of indirect prompt injection. Ingestion points: Reads a plan file from the workspace in Step 1. Boundary markers: Lacks explicit instructions to isolate or treat plan file content as untrusted data or delimitation. Capability inventory: Execution of arbitrary developer tasks, including file modifications and tool usage as defined in the plan. Sanitization: No validation or sanitization of plan contents is specified.
- [NO_CODE]: The skill consists only of natural language instructions and does not include executable scripts or external software dependencies.
Audit Metadata