cc-ultraplan
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The workflow allows data generated in a cloud session to be integrated into the local agent context, creating a surface for indirect prompt injection.
- Ingestion points: Approved plans are serialized and sent from the cloud environment back to the local terminal session (SKILL.md).
- Boundary markers: The browser interface requires the user to manually review, comment on, and approve plan sections before they are sent to the CLI.
- Capability inventory: The skill allows the agent to use
ReadandBashtools. - Sanitization: The instructions do not describe any automated sanitization or security filtering for the plan data received from the remote source.
Audit Metadata