alan-plan

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external, untrusted data to generate plans, which creates a surface for indirect prompt injection.
  • Ingestion points: Instructions in SKILL.md direct the agent to ingest data from task descriptions, linked context, codebase exploration, and existing artifacts via mcp__alan__get_artifact.
  • Boundary markers: There are no instructions in SKILL.md regarding the use of delimiters or directives to ignore instructions embedded in the ingested data.
  • Capability inventory: The agent is authorized in SKILL.md to persist and modify content using mcp__alan__create_plan, mcp__alan__update_artifact, and mcp__alan__add_artifact_comment.
  • Sanitization: No procedures for sanitizing or validating external content are defined in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 01:32 PM
Security Audit — agent-trust-hub — alan-plan