breakdown-plan

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides examples of GitHub Action workflows that reference 'actions/github-script@v7'. This is an official action from the GitHub organization and is considered a safe reference for automation purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest local documentation files such as PRDs and technical breakdowns. While this represents an attack surface for indirect prompt injection, the skill lacks dangerous capabilities like arbitrary command execution or network access, and the data source (internal project docs) is generally considered low-risk. No specific sanitization logic is mentioned, but the intended use case is primarily documentation generation.
  • [COMMAND_EXECUTION]: Although the skill provides templates for GitHub Action workflows involving script execution, these are intended to be part of the user's CI/CD infrastructure rather than being executed by the agent skill itself at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:32 PM
Security Audit — agent-trust-hub — breakdown-plan