helm-plan
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-supplied feature lists and initiatives in Step 1, creating an indirect prompt injection surface.
- Ingestion points: User input gathered in 'Step 1: Gather the Input' in SKILL.md.
- Boundary markers: Absent; no instructions exist to delimit user data or warn the agent against embedded instructions.
- Capability inventory: The skill uses tools including 'Bash', 'Write', 'Edit', and 'WebFetch' as defined in the YAML frontmatter.
- Sanitization: No sanitization or validation of user-provided data is specified before processing or scoring.
- [SAFE]: The skill references an external formatting guideline 'docs/output-kit.md' and a custom reporting command '/atlas-report'. These appear to be vendor-specific environment features from 'tonone-ai' rather than malicious patterns.
Audit Metadata