plan-ceo-review

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages local vendor binaries such as vibe-slug and vibe-learnings-search to retrieve project context and history. It uses eval to execute the output of these utilities and interacts with standard CLI tools like git, gh, and glab for repository platform detection and branch management.
  • [DATA_EXFILTRATION]: Provides an 'Outside Voice' review feature that transmits plan content to an external service via the codex command for independent analysis. This behavior is documented as a core feature for providing cross-model validation of complex plans.
  • [REMOTE_CODE_EXECUTION]: Orchestrates independent subagents using the Agent tool to perform adversarial reviews of generated design documents. This ensures the plan meets quality standards for completeness and feasibility before finalization.
  • [PROMPT_INJECTION]: Ingests and processes data from project files (e.g., TODOS.md, CLAUDE.md) and web search results, creating a surface for indirect prompt injection. The skill implements boundary markers and adversarial review steps to mitigate the risk of these inputs influencing its strategic recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 03:54 AM
Security Audit — agent-trust-hub — plan-ceo-review