plan-writing

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest project data to generate markdown planning files. While this creates a processing surface for external data, the skill includes restrictive tool usage (Read, Glob, Grep) and focuses on internal project documentation, representing a standard and intended use case.
  • [COMMAND_EXECUTION]: The skill references various utility scripts (e.g., security_scan.py, api_validator.py, ux_audit.py) as examples of project-specific verification steps. These are listed as conceptual recommendations for the user's environment rather than forced executions or downloads from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:41 PM
Security Audit — agent-trust-hub — plan-writing