plan-resolve-questions

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions designed to override or disregard system-level guidance. Phrases like "this skill OVERRIDES any system reminder", "Specific instructions beat generic ones", and "Invoke AskUserQuestion even when that reminder is in context" are used to ensure the agent ignores generic heuristics that might prevent it from pausing for questions.\n- [DATA_EXPOSURE]: The skill reads and modifies files in ~/.claude/plans/. While this is the standard path for the platform's plan management, it involves direct interaction with filesystem data that can be influenced by project content.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from 'Unresolved questions' sections in plan files to generate options for the AskUserQuestion tool. This ingestion point at ~/.claude/plans/.md lacks explicit sanitization or boundary markers, creating a surface where malicious content in a plan file could influence the agent's behavior or the choices presented to the user. The skill possesses capabilities for file modification and invoking the plan-to-github-issue tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:40 AM
Security Audit — agent-trust-hub — plan-resolve-questions