make-plan
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md is transparent and reviewable, with no hidden execution paths or obfuscated content. However, the skill does materially weaken instruction/data boundaries by treating untrusted external content in ways that blur the line with policy-level instructions, which increases prompt-injection risk. Behavior analysis was not run, so downstream impact relative to a no-skill baseline remains unassessed—this gap, combined with the boundary-weakening finding, supports the AT_RISK verdict. Confidence is medium because while the injection concern is concrete, finite testing cannot fully characterize exploitation scenarios, and the missing behavior analysis leaves a meaningful blind spot.
The scanned SKILL.md is materially reviewable, with no hidden execution path or secret-like content detected in the markdown.
The skill increases prompt injection risk by weakening trust boundaries around untrusted external content treated as policy.
Behavior analysis was not run.
Untrusted external content treated as policy