execute-plan

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill requires the agent to recite a specific commitment statement ("I will execute this plan to completion. All the 20 tasks will be addressed and marked as DONE.") which acts as an instruction override, compelling the agent to adhere strictly to instructions found in external files regardless of their potential risk.\n- [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection by processing untrusted data from external files and instructing the agent to execute all actions contained within them.\n
  • Ingestion points: Markdown files read from the plans/ directory as specified in Step 2 of the execution process.\n
  • Boundary markers: Absent. The instructions do not provide delimiters or warnings to treat plan content as untrusted data.\n
  • Capability inventory: The instruction to "Execute all actions required to complete the task" grants the content of the external file access to any tool or command available to the agent.\n
  • Sanitization: Absent. There is no mention of filtering, escaping, or validating the content of the plan files before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 10:24 PM
Security Audit — agent-trust-hub — execute-plan