writing-plans
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from requirements and repository comments to generate implementation plans. This creates a surface where an attacker could embed instructions in an issue or PR to influence the agent's behavior during the planning phase.
- Ingestion points:
SKILL.md(Research and Decide, Step 1) instructs the agent to read live requirements and relevant comments. - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested text.
- Capability inventory: The skill is restricted to reading repository content and publishing implementation plans as issue comments. It explicitly states that it does not modify implementation files or dispatch autonomous executors, which significantly limits the potential impact of an injection.
- Sanitization: No explicit validation or sanitization routines for external data are specified.
Audit Metadata