planning

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes structured verification gates and mandatory user confirmation tools (AskUserQuestion) to prevent external inputs from overriding the defined planning logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages its attack surface when processing external codebase data by employing multiple defense-in-depth measures. Ingestion points occur during codebase search and intent clarification (Step 1). Boundary markers include progressive gates and an independent subagent review step (Step 8). Capability inventory includes plan file creation (Step 7) and internal tool chaining. Sanitization is achieved through structured phase templates and deterministic DAG validation.
  • [DYNAMIC_EXECUTION]: The skill dispatches a subagent for structural review of generated plans, serving as a platform-native verification mechanism rather than an arbitrary code execution vector.
  • [REMOTE_CODE_EXECUTION]: Internal skills within the code-foundations namespace are dynamically loaded to provide specialized context; these operations remain within the trusted vendor ecosystem and follow defined platform patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:29 PM
Security Audit — agent-trust-hub — planning