plan-writing
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest project data to generate markdown planning files. While this creates a processing surface for external data, the skill includes restrictive tool usage (Read, Glob, Grep) and focuses on internal project documentation, representing a standard and intended use case.
- [COMMAND_EXECUTION]: The skill references various utility scripts (e.g.,
security_scan.py,api_validator.py,ux_audit.py) as examples of project-specific verification steps. These are listed as conceptual recommendations for the user's environment rather than forced executions or downloads from untrusted sources.
Audit Metadata