skills/reforma-dev/agentflow/plan/Gen Agent Trust Hub

plan

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a template and procedural guide for software development planning. It does not contain instructions for data exfiltration, unauthorized file access, or remote code execution. The primary activity is the generation of project documentation within the '.agentflow/' directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an organizational framework for project decisions, which involves processing potentially untrusted data from the conversation history.
  • Ingestion points: The skill processes 'settled decisions' from the user and reads existing plan files from the repository to generate task lists.
  • Boundary markers: While the skill uses structured headers, it does not specify explicit boundary markers or isolation instructions to prevent embedded commands in the source data from affecting the plan's logic.
  • Capability inventory: The skill involves writing to the file system (creating '.agentflow/plan.md') and generating suggested verification shell commands for the user to run.
  • Sanitization: The prompt does not define specific input validation or sanitization rules for the information it structures into the plan output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 04:28 PM
Security Audit — agent-trust-hub — plan