executing-plans

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to load and execute tasks from external plan files, which introduces a risk of indirect prompt injection. Ingestion points: Reads a plan file from the workspace in Step 1. Boundary markers: Lacks explicit instructions to isolate or treat plan file content as untrusted data or delimitation. Capability inventory: Execution of arbitrary developer tasks, including file modifications and tool usage as defined in the plan. Sanitization: No validation or sanitization of plan contents is specified.
  • [NO_CODE]: The skill consists only of natural language instructions and does not include executable scripts or external software dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 07:36 PM
Security Audit — agent-trust-hub — executing-plans