tailrocks-improve-plan
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core logic involves processing untrusted repository content, reports, and web content. While it includes explicit 'Runtime trust' guidelines (references/runtime-trust.md) to treat this content as data rather than instructions, the attack surface for indirect injection remains inherent to its design.
- [METADATA_POISONING]: The skill uses detailed instructions to manage metadata within
plans/README.mdand YAML frontmatter. While not deceptive in intent, these mechanisms could be targeted to influence agent behavior through structural manipulation or 'rejection' row poisoning.
Audit Metadata