skills/sehoon787/my-claude/ralplan/Gen Agent Trust Hub

ralplan

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill serves as an orchestrator that invokes other internal tools and skills within the oh-my-claudecode namespace (specifically omc-plan, team, and ralph). These calls are central to its functional purpose as a planning and delegation wrapper.
  • [PROMPT_INJECTION]: The skill documentation includes 'bypass' prefixes (e.g., force:, !) and specific phrases (e.g., 'just do it', 'skip planning') that allow users to override the 'Pre-Execution Gate' or planning phases. These are presented as functional overrides for power users and do not represent attempts to subvert the agent's core safety guardrails.
  • [EXTERNAL_DOWNLOADS]: The skill mentions the use of 'Codex CLI' for Architect and Critic passes if available. This is a conditional check for a local developer tool and does not involve automated remote script execution or untrusted downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:43 AM
Security Audit — agent-trust-hub — ralplan