plan-ceo-review
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted repository data (e.g.,
AGENTS.md,TODO.md, and code files) to guide the agent's review process. - Ingestion points: The
PRE-REVIEW SYSTEM AUDITsection inSKILL.mdinstructs the agent to read project-local instructions, architecture documents, and source code files. - Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to ignore embedded instructions found within the repository files.
- Capability inventory: The skill uses subprocess calls to execute read-only commands (
git log,git diff,git stash,grep,find) inSKILL.md. It explicitly forbids making code changes or starting implementation during the review phase. - Sanitization: There is no evidence of sanitization, validation, or escaping of the content ingested from the external repository files before it is processed by the agent.
Audit Metadata