writing-plans
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts or binary executables.- [PROMPT_INJECTION]: The skill processes user-provided specifications to generate executable implementation plans, creating a surface for indirect prompt injection.
- Ingestion points: The skill ingests 'spec or requirements' from the user as defined in the overview and usage context.
- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the user-provided specification.
- Capability inventory: Generated plans include file system modifications and shell command execution (e.g., pytest, git), which are designed to be run by execution-focused sub-skills like 'executing-plans'.
- Sanitization: The skill lacks instructions for sanitizing or validating user input before including it in generated plans.
Audit Metadata