writing-plans

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts or binary executables.- [PROMPT_INJECTION]: The skill processes user-provided specifications to generate executable implementation plans, creating a surface for indirect prompt injection.
  • Ingestion points: The skill ingests 'spec or requirements' from the user as defined in the overview and usage context.
  • Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the user-provided specification.
  • Capability inventory: Generated plans include file system modifications and shell command execution (e.g., pytest, git), which are designed to be run by execution-focused sub-skills like 'executing-plans'.
  • Sanitization: The skill lacks instructions for sanitizing or validating user input before including it in generated plans.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 07:08 AM
Security Audit — agent-trust-hub — writing-plans