writing-plans

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection vulnerability due to ingestion of untrusted content from GitHub issues and PRDs.\n
  • Ingestion points: The skill reads specifications from the work/PRD GitHub issue body and its associated comments.\n
  • Boundary markers: No specific delimiters or instructions are used to distinguish between requirements and potentially malicious instructions within the input data.\n
  • Capability inventory: The skill generates executable bash commands and code snippets, and utilizes the gh issue comment command to output data.\n
  • Sanitization: The instructions lack guidance on sanitizing or validating external input before incorporating it into the generated plan.\n- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI tool to manage issue comments.\n
  • Evidence: The Storing the Plan section in SKILL.md explicitly instructs the use of gh issue comment <N> --body-file - to post plan content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 10:05 AM
Security Audit — agent-trust-hub — writing-plans