executing-plans

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute local utility scripts provided in the skill package (scripts/plan-header.mjs and scripts/delivery-status.mjs) using Node.js. It also performs standard Git operations and executes verification commands specified within the external implementation plan.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from GitHub issues and comments to guide its execution logic, creating a vulnerability surface.
  • Ingestion points: SKILL.md (Sections 1 and 2) and references/executor-brief.md specify reading the live issue body and plan comments from the repository tracker to establish the implementation contract.
  • Boundary markers: The skill employs a fingerprinting mechanism in scripts/plan-header.mjs to detect unauthorized changes to requirements and includes explicit instructions to ignore content from unrelated comments, logs, or external links.
  • Capability inventory: The skill allows modification of files (Touch paths in plan), execution of shell commands (Check steps in plan), Git operations (branching, pushing, PR creation), and tracker updates.
  • Sanitization: While the skill validates the integrity of the plan against the original requirements using SHA-256 hashes, it does not perform sanitization on the shell commands or file paths defined within the plan content itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 12:10 PM
Security Audit — agent-trust-hub — executing-plans