recipe-front-plan

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a high-level orchestrator for documentation and planning tasks and does not contain any executable code or dangerous system commands.- [SAFE]: No evidence of malicious patterns such as prompt injection, data exfiltration, or obfuscation was found in the analyzed files.- [SAFE]: The execution process includes multiple human-in-the-loop (HITL) checkpoints, specifically requiring explicit user approval for design document selection and final plan content before the task is considered complete.- [SAFE]: Analysis of indirect prompt injection surfaces: Ingestion points: Reads design documents from the 'docs/design/' directory. Boundary markers: No explicit delimiter markers are used when passing file paths to sub-agents. Capability inventory: Orchestrates sub-agents ('acceptance-test-generator', 'work-planner', 'document-reviewer') but performs no direct shell commands or file writes within this orchestrator script. Sanitization: No specific input sanitization or filtering is performed on the design document content. Mitigation: The risk is mitigated by a mandatory human-in-the-loop approval step before the workflow is finalized.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 10:14 PM
Security Audit — agent-trust-hub — recipe-front-plan